Pull requests / #321

#321 serve: add CORS preflight (OPTIONS), reverse-proxy header support, and X-Accel-Buffering for SSE

closed · @BlitzenCats · 0 comments · View on GitHub

Server & APISecurity

Description

### Summary
This PR adds support for web-based API clients (CORS) and reverse proxies / tunnels (such as Cloudflare Tunnel, Tailscale Funnel, and Nginx) when remotely serving Strata or connecting third-party web frontends.

### Key Changes
1. **CORS & Preflight (\OPTIONS\ 204 No Content)**:
   - Implements \do_OPTIONS\ returning \204 No Content\ with \Access-Control-Allow-Origin: *\, \Access-Control-Allow-Methods: GET, POST, OPTIONS\, and \Access-Control-Allow-Headers: *\.
   - Without this, browser-based clients (such as Open WebUI, LibreChat, Chatbox, or browser extensions) making CORS preflight checks received \501 Unsupported method ('OPTIONS')\.
   - Adds standard CORS headers to JSON responses.

2. **Reverse Proxy Origin Validation**:
   - Updates \_own_page\ in \serve/server.py\ to inspect \X-Forwarded-Host\ and recognize proxy headers (\CF-Ray\, \CF-Connecting-IP\, \X-Forwarded-For\).
   - Reverse proxies typically rewrite \Host: 127.0.0.1:8080\ while retaining \Origin: https://<external-domain>\. Previously, this mismatch caused \_own_page\ to trigger \403 Forbidden\ on settings and MCP tools when accessing Strata's web UI remotely through a tunnel.

3. **SSE Stream Buffering (\X-Accel-Buffering: no\)**:
   - Adds \X-Accel-Buffering: no\ to \_sse\ response headers to instruct edge/reverse proxies (Cloudflare, Nginx) not to buffer tokens, ensuring real-time streaming over Server-Sent Events.

4. **Unit Tests**:
   - Added tests in \serve/test_server.py\ covering CORS preflights, response headers, and reverse-proxy forwarded origin handling (all 80+ server unit tests pass).

---
*Authored by @BlitzenCats & Gemini*

Related on strata.com

Editorial links to help you install, pick models, or read release notes — not part of the upstream thread.