Skip to content

Enable CORS for browser integration clients - #31

Merged
michielbdejong merged 1 commit into
mainfrom
codex/browser-integrations
Sep 9, 2026
Merged

michielbdejong merged 1 commit into
mainfrom
codex/browser-integrations

Conversation

@michielbdejong

@michielbdejong michielbdejong commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Allow browser-based Atomic clients to call LocalThought directly, including consuming the rotating connection code and following pagination without an AtomicServer HTTP intermediary.

  • Handle CORS preflights for explicit Authorization and Content-Type headers.
  • Expose X-Connection-Code, Link, Retry-After, ETag, X-Total-Count and X-Next-Page.
  • Keep cookie credentials disabled for CORS; login and consent remain top-level browser navigations.

Validation: all 39 tests pass, including a new browser preflight/exposed-header regression. Live browser OAuth requires deploying this change; this PR does not deploy it.

Companion PRs: ontola/atomic-server#1401 and localthought/syncables-rs#29.

@michielbdejong
michielbdejong merged commit bc02f13 into main Sep 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant