Spaces:
Running on Zero
Running on Zero
security: overwrite Gradio's reflected CORS on /respite/*
Browse files
app.py
CHANGED
|
@@ -882,6 +882,35 @@ def _patched_create_app(blocks, **kwargs):
|
|
| 882 |
except Exception as _se:
|
| 883 |
_log(f"searxng bridge registration failed: {_se}")
|
| 884 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 885 |
_log("Routes injected via create_app monkey-patch")
|
| 886 |
return fa_app
|
| 887 |
|
|
|
|
| 882 |
except Exception as _se:
|
| 883 |
_log(f"searxng bridge registration failed: {_se}")
|
| 884 |
|
| 885 |
+
# ββ CORS gate for /respite/* ββββββββββββββββββββββββββββββββββββββββββββ
|
| 886 |
+
# Gradio installs a global CORS middleware that reflects the caller's
|
| 887 |
+
# Origin and sets `Access-Control-Allow-Credentials: true`. Applied to the
|
| 888 |
+
# whole app, that turns every route we inject below into a cross-origin
|
| 889 |
+
# readable endpoint β including the audio, search and inference routes,
|
| 890 |
+
# which have no auth of their own. The per-route headers set in
|
| 891 |
+
# node_probe.py are not enough on their own: this middleware runs outside
|
| 892 |
+
# the route handlers and re-adds its own on the way out.
|
| 893 |
+
#
|
| 894 |
+
# So it is added here, after Gradio's (Starlette runs the most recently
|
| 895 |
+
# added middleware outermost), and it rewrites the headers on the way out
|
| 896 |
+
# of the inner stack. Scoped to /respite/* so the Gradio UI itself is left
|
| 897 |
+
# alone.
|
| 898 |
+
try:
|
| 899 |
+
from node_probe import cors_headers as _respite_cors_headers
|
| 900 |
+
|
| 901 |
+
@fa_app.middleware("http")
|
| 902 |
+
async def _respite_cors_gate(request, call_next):
|
| 903 |
+
response = await call_next(request)
|
| 904 |
+
if request.url.path.startswith("/respite/"):
|
| 905 |
+
for name in list(response.headers.keys()):
|
| 906 |
+
if name.lower().startswith("access-control-"):
|
| 907 |
+
del response.headers[name]
|
| 908 |
+
for name, value in _respite_cors_headers(request).items():
|
| 909 |
+
response.headers[name] = value
|
| 910 |
+
return response
|
| 911 |
+
except Exception as _ce:
|
| 912 |
+
_log(f"respite CORS gate not installed: {_ce}")
|
| 913 |
+
|
| 914 |
_log("Routes injected via create_app monkey-patch")
|
| 915 |
return fa_app
|
| 916 |
|