Fix dev proxy so cookies work when proxying remote HTTPS Galaxy servers

Without changeOrigin the upstream saw Host: localhost:5173 and could behave
unexpectedly. More importantly, cookies from HTTPS upstreams carry Secure and
SameSite=None, which browsers silently drop over http://localhost, so
galaxysession was never stored and /context returned session_csrf_token: null.

Strip Secure and rewrite SameSite=None → Lax in the proxyRes handler, remove
the domain attribute via cookieDomainRewrite, and enable changeOrigin and
secure:false unconditionally for the dev proxy.
This commit is contained in:
mvdbeek
2026-06-17 12:57:36 +02:00
parent 13acce10ba
commit 62df3eb783
+17 -2
View File
@@ -160,8 +160,23 @@ export default defineConfig(({ command }) => ({
// Proxy everything except Vite's own routes to Galaxy backend
"^/(?!(@|src/|node_modules/|__vite))": {
target: process.env.GALAXY_URL || "http://127.0.0.1:8080",
changeOrigin: !!process.env.CHANGE_ORIGIN,
secure: process.env.CHANGE_ORIGIN ? false : true,
changeOrigin: true,
secure: false,
cookieDomainRewrite: "",
configure: (proxy) => {
// Strip Secure flag and fix SameSite from upstream HTTPS cookies so
// they are accepted by the browser on http://localhost.
proxy.on("proxyRes", (proxyRes) => {
const cookies = proxyRes.headers["set-cookie"];
if (cookies) {
proxyRes.headers["set-cookie"] = cookies.map((cookie) =>
cookie
.replace(/;\s*Secure/gi, "")
.replace(/;\s*SameSite=None/gi, "; SameSite=Lax")
);
}
});
},
},
},
cors: true,