mirror of
https://github.com/cloudflare/vinext.git
synced 2026-05-09 08:25:34 +02:00
[PR #95] [MERGED] fix: use Host header for server action origin check #304
Labels
No labels
enhancement
enhancement
good first issue
help wanted
nextjs-tracking
nextjs-tracking
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/vinext#304
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/cloudflare/vinext/pull/95
Author: @southpolesteve
Created: 2/26/2026
Status: ✅ Merged
Merged: 2/26/2026
Merged by: @southpolesteve
Base:
main← Head:fix/host-header-origin-check📝 Commits (1)
6878aa1fix: use Host header for server action origin check📊 Changes
2 files changed (+36 additions, -1 deletions)
View changed files
📝
packages/vinext/src/server/app-dev-server.ts(+5 -1)📝
tests/app-router.test.ts(+31 -0)📄 Description
Summary
Changes the server action origin validation to prefer the Host header over X-Forwarded-Host, matching the trusted-host logic already used in the production server.
X-Forwarded-Host can be freely set by the client, so using it in the origin comparison allows the check to be bypassed by sending a matching Origin and X-Forwarded-Host pair. The Host header is set by the HTTP stack and is the correct value to compare against.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.