Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

ci: E2E web WebSocket tests fail since relic 2.0.0-rc.1 rejects cross-origin WebSocket upgrades

Aperta
#5,642 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@nielsenko ci sta già lavorando.

Dal 3/9/2026.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

area: web server bug

Summary

Since 2026-08-25 ~12:30 UTC every WebSocket-based test in the Serverpod E2E web tests CI job fails, on main and on all open PRs, with:

Method stream WebSocket failed to connect with error: WebSocketChannelException: WebSocketException: Failed to connect WebSocket

Cause: relic 2.0.0-rc.1 (published 2026-08-25 12:23 UTC). packages/serverpod/pubspec.yaml depends on relic: ^2.0.0-beta.1, no lockfile is tracked, so every CI run since then resolves rc.1. Its changelog:

BREAKING: Cross-origin WebSocket upgrades are rejected with 403 by default; pass WebSocketUpgrade(..., allowAnyOrigin: true) to accept them. Only the host is compared, since a TLS-terminating proxy changes scheme and port

The browser test page is served by dart test from http://localhost:<port> while the client opens ws://serverpod_test_server:8080/v1/websocket, so relic's new same-host check returns a bare 403 Forbidden before Serverpod's handler runs. The vm shards pass because dart:io clients send no Origin header.

Impact beyond CI

This is not only a test problem: any Serverpod 4 deployment that serves its web client from a different host than the API server (e.g. app.example.com → api.example.com) loses method streaming / WebSockets as soon as it picks up relic rc.1, even though Serverpod's own allowedOrigins gate (Server._isOriginDisallowed, #5555) would have allowed it.

Fix

Serverpod already enforces its own origin policy immediately before the upgrade (packages/serverpod/lib/src/server/server.dart, _dispatchWebSocket), so it should opt out of relic's coarser default:

return WebSocketUpgrade(allowAnyOrigin: true, (webSocket) async { ... });

Follow-ups worth considering:

  • Decide whether an unset allowedOrigins should mean "allow any origin" (pre-rc.1 behaviour, restored by the fix) or "same host only" (relic's new default).
Lingua principale
Dart
Stelle
3.3k
Fork
382
Merge medio
1g 4h
PR unite (30g)
65

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di serverpod/serverpod

Tutte le issue di serverpod/serverpod

Issue simili

Altre issue su Dart

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.