From 62df3eb78367f20bd477fdae62f6d6c18aeea5b9 Mon Sep 17 00:00:00 2001 From: mvdbeek Date: Wed, 17 Jun 2026 12:57:36 +0200 Subject: [PATCH] Fix dev proxy so cookies work when proxying remote HTTPS Galaxy servers MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Without changeOrigin the upstream saw Host: localhost:5173 and could behave unexpectedly. More importantly, cookies from HTTPS upstreams carry Secure and SameSite=None, which browsers silently drop over http://localhost, so galaxysession was never stored and /context returned session_csrf_token: null. Strip Secure and rewrite SameSite=None → Lax in the proxyRes handler, remove the domain attribute via cookieDomainRewrite, and enable changeOrigin and secure:false unconditionally for the dev proxy. --- client/vite.config.mjs | 19 +++++++++++++++++-- 1 file changed, 17 insertions(+), 2 deletions(-) diff --git a/client/vite.config.mjs b/client/vite.config.mjs index 9620700ba7a..1c0cd1dd0b8 100644 --- a/client/vite.config.mjs +++ b/client/vite.config.mjs @@ -160,8 +160,23 @@ export default defineConfig(({ command }) => ({ // Proxy everything except Vite's own routes to Galaxy backend "^/(?!(@|src/|node_modules/|__vite))": { target: process.env.GALAXY_URL || "http://127.0.0.1:8080", - changeOrigin: !!process.env.CHANGE_ORIGIN, - secure: process.env.CHANGE_ORIGIN ? false : true, + changeOrigin: true, + secure: false, + cookieDomainRewrite: "", + configure: (proxy) => { + // Strip Secure flag and fix SameSite from upstream HTTPS cookies so + // they are accepted by the browser on http://localhost. + proxy.on("proxyRes", (proxyRes) => { + const cookies = proxyRes.headers["set-cookie"]; + if (cookies) { + proxyRes.headers["set-cookie"] = cookies.map((cookie) => + cookie + .replace(/;\s*Secure/gi, "") + .replace(/;\s*SameSite=None/gi, "; SameSite=Lax") + ); + } + }); + }, }, }, cors: true,