Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

workspace: confirm the IDE extension calls the new serve routes from its host process, not a webview

Aperta
#1,385 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
35/100
Tipo di issue
Bug
Chiarezza
Da chiarire
Stato di attività
Attiva
Stack tecnologico
typescript
Ambito
devtools, security

Direzione di ricerca

Start with the route guard and route definitions in packages/opencode/src/server/server.ts, then inspect where the IDE extension's Refresh, Sync, and Publish actions issue their requests. Confirm whether calls originate in the extension host or a webview; done means host-origin requests succeed without 403, or webview calls are routed through the host without weakening the refusal.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Found during the v0.12.4 release review. Needs confirmation against the IDE extension; not verifiable from this repo.

v0.12.4 adds serve routes for the extension: POST /altimate/workspace/refresh, POST /altimate/workspace/sync, GET /altimate/skill/publishable and POST /altimate/skill/publish. All four go through workspaceRouteRefusal (packages/opencode/src/server/server.ts), which refuses any request a browser labels cross-site (Sec-Fetch-Site), any request with an Origin when OPENCODE_SERVER_PASSWORD is unset, and any other origin when it is set. Native clients (the extension host process, curl) send neither header and are allowed.

If the extension calls these routes from a webview fetch (a Chromium context that sends Origin / Sec-Fetch-Site) rather than from the extension host, every call is refused with 403 and the panel's Refresh / Sync / Publish actions do not work.

To do: confirm where the extension issues these requests. If from a webview, route them through the extension host (preferred — keeps the browser-origin refusal intact), rather than loosening the gate.

Lingua principale
TypeScript
Stelle
805
Fork
122
Merge medio
2g 10h
PR unite (30g)
63

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di AltimateAI/altimate-code

Tutte le issue di AltimateAI/altimate-code

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.