Skip to content

Allow Cosmos tunnel domains in component preview - #3532

Merged
sawka merged 1 commit into
mainfrom
cosmos/sawka/preview-domains
Oct 1, 2026
Merged

sawka merged 1 commit into
mainfrom
cosmos/sawka/preview-domains

Conversation

@sawka

@sawka sawka commented Oct 1, 2026

Copy link
Copy Markdown
Member

Summary

  • Allow augmentusercontent.com and its subdomains in the component preview Vite server using the domain-scoped allowedHosts setting.
  • Keep host validation enabled for unrelated domains.

Validation

  • Localhost, the Cosmos tunnel hostname, and a nested augmentusercontent.com subdomain returned HTTP 200 on port 7007.
  • Unrelated and suffix-spoofed domains returned HTTP 403.
  • git diff --check passed.
  • User confirmed the preview works through the Cosmos tunnel.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Deploying waveterm with  Cloudflare Pages  Cloudflare Pages

Latest commit: d52c547
Status: ✅  Deploy successful!
Preview URL: https://a1a4fa21.waveterm.pages.dev
Branch Preview URL: https://cosmos-sawka-preview-domains.waveterm.pages.dev

View logs

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 856f1cc1-b80f-453d-8c58-9a9fefdb8472

📥 Commits

Reviewing files that changed from the base of the PR and between c58bf7f and d52c547.

📒 Files selected for processing (1)
  • frontend/preview/vite.config.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


Walkthrough

The Vite development server configuration now allows hosts ending in .augmentusercontent.com.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Merge Risk: ⚪ Minimal · up to d52c5

The preview server accepts Cosmos tunnel domains while preserving host validation for unrelated domains. The change is ready to merge after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to d52c5

The change remains narrowly scoped and preserves host validation for unrelated domains. However, trusting the entire tunnel domain depends on hostname ownership and routing isolation that have not been established. No exploitable cross-preview access has been verified.

Retained concerns

  • Low · security · inferred: The host gate now accepts the entire augmentusercontent.com namespace rather than only a specific preview hostname. If an attacker-controlled matching hostname can reach another preview, the expanded gate would accept it. Namespace ownership and routing isolation remain unverified; cross-preview access is not established.
Security review details

Security Blast Radius

  • inferred — The directly affected resource is a reachable standalone preview server and the content it serves. The evidence does not establish cross-tenant reachability, backend access, or a broader service exposure.

Security Findings and Attack Paths

  • observed — The security candidate remains deferred, not verified. Its unresolved prerequisite is whether attacker-controlled matching hostnames can reach another preview given external hostname ownership, DNS control, and routing isolation.

Trust Boundaries and Controls

  • observed — The configuration uses a domain-scoped list rather than disabling host validation. PR-reported validation rejected unrelated and suffix-spoofed domains; this supports host filtering but does not establish tenant isolation.

Hardening Proposals

  • proposed — Confirm who can allocate matching hostnames and how routing isolates preview instances. If that namespace is not a sufficient trust boundary, consider limiting acceptance to the assigned preview hostname.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main change: allowing Cosmos tunnel domains in the component preview.
Description check ✅ Passed The description is directly related to the changeset and explains the allowed domains, validation behavior, and test results.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.

Warning

Some tools did not complete. Review the errors below.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install timed out. The project may have too many dependencies for the sandbox.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sawka
sawka merged commit 6d61b99 into main Oct 1, 2026
5 of 8 checks passed
@sawka
sawka deleted the cosmos/sawka/preview-domains branch October 1, 2026 17:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant