Commit 9119d86
fix: ensure impersonation always goes through authenticated path
Two issues caused impersonation to silently fall back to the anonymous
public client (empty mode, no actions):
1. Auth middleware: when X-Wasteland header was missing (race condition,
impersonation without explicit upstream), multi-wasteland users hit
passOrBlock which let GET requests through without auth context. Now
GET requests always default to the first upstream.
2. Cache-Control: hosted mode used "public" which let browsers cache
responses across auth states. Changed to "private" so per-user
responses are never served from a shared cache.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>1 parent 1eacbab commit 9119d86
2 files changed
Lines changed: 15 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
71 | 71 | | |
72 | 72 | | |
73 | 73 | | |
74 | | - | |
| 74 | + | |
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
| |||
113 | 113 | | |
114 | 114 | | |
115 | 115 | | |
116 | | - | |
| 116 | + | |
117 | 117 | | |
118 | 118 | | |
119 | 119 | | |
120 | 120 | | |
121 | 121 | | |
122 | 122 | | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
123 | 132 | | |
124 | 133 | | |
125 | 134 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
113 | 113 | | |
114 | 114 | | |
115 | 115 | | |
116 | | - | |
117 | | - | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
118 | 120 | | |
119 | 121 | | |
120 | 122 | | |
| |||
0 commit comments