Skip to content

fix(sidecar): preserve Vary origin when gzip is enabled#170

Closed
lawyered0 wants to merge 1 commit into
koala73:mainfrom
lawyered0:codex/critical-bug-sweep-3
Closed

fix(sidecar): preserve Vary origin when gzip is enabled#170
lawyered0 wants to merge 1 commit into
koala73:mainfrom
lawyered0:codex/critical-bug-sweep-3

Conversation

@lawyered0

Copy link
Copy Markdown
Contributor

Summary

  • fix sidecar header handling so gzip compression does not clobber existing Vary values
  • preserve CORS cache correctness by keeping Origin in Vary when Accept-Encoding is added
  • add a regression test for compressed responses

Problem

In local-api-server.mjs, compressed responses set:

  • headers['vary'] = 'Accept-Encoding'

That overwrote the prior Origin token, despite the response being origin-sensitive (Access-Control-Allow-Origin is set dynamically). This can cause incorrect cache behavior and CORS inconsistencies.

Fix

  • add appendVary(existing, token) helper
  • replace direct assignments with token-merging:
    • merge Origin
    • merge Accept-Encoding

Regression Coverage

Added test:

  • preserves Origin in Vary when gzip compression is applied

It verifies:

  • response is gzip-encoded
  • Access-Control-Allow-Origin reflects request origin
  • Vary includes both origin and accept-encoding

Validation

  • npm run typecheck
  • npm run test:sidecar
  • npm run test:data
  • npm run build

@vercel

vercel Bot commented Feb 20, 2026

Copy link
Copy Markdown

@lawyered0 is attempting to deploy a commit to the eliehabib projects Team on Vercel.

A member of the Team first needs to authorize it.

@koala73 koala73 closed this in cb24b22 Feb 20, 2026
facusturla pushed a commit to facusturla/worldmonitor that referenced this pull request Feb 27, 2026
Replace naive string concatenation for Vary header with appendVary()
that parses existing tokens and deduplicates case-insensitively.
Prevents duplicate Vary tokens when both Origin and Accept-Encoding
are added.

Closes koala73#170

Co-authored-by: Lawyered <[email protected]>
koala73 added a commit that referenced this pull request Apr 11, 2026
…riter

Resolves all 5 critical findings from the multi-agent code review of PR #2940.
End-to-end smoke test passes for all 8 regions with confidence=1.0.

P1 #166: health-seed-meta-not-in-keys-loops
  - Add regionalSnapshots to STANDALONE_KEYS in api/health.js
  - Without this, the SEED_META entry was dead wiring and the 12h staleness
    budget was unobservable. Same failure mode as the 'empty data ok keys
    bootstrap blind spot' the team has hit before.

P1 #167: oref-trigger-key-not-in-freshness-registry
  - Add relay:oref:history:v1 to FRESHNESS_REGISTRY (the canonical OREF key
    written by ais-relay, not the wrong intelligence:oref-alerts:v1 that the
    code was originally reading).
  - Update trigger-evaluator to read activeAlertCount/historyCount24h from
    the actual relay:oref:history:v1 payload shape.
  - oref_cluster trigger now fires when activeAlertCount > 10 (verified
    end-to-end against mock data).

P1 #168: zombie-freshness-registry-keys
  - Remove 4 freshness registry entries that no compute module reads:
    supply_chain:shipping_stress, energy:chokepoint-flows,
    intelligence:advisories-bootstrap, market:commodities-bootstrap.
  - These were dragging snapshot_confidence below 1.0 and wasting Redis
    pipeline reads. Add a header comment forbidding speculative entries.

P1 #169: diff-field-leaks-into-persisted-snapshot
  - Change computeSnapshot to return { snapshot, diff } separately so the
    diff is consumed locally for inferTriggerReason and never serialized
    into the persisted snapshot. The diff field was not part of the
    RegionalSnapshot type and would have broken Phase 1 proto codegen.
  - Update main() to destructure { snapshot } before persistSnapshot.

P1 #170: jsdoc-types-not-enforced-jsconfig-missing
  - Add scripts/seed-regional-snapshots.mjs and scripts/regional-snapshot/**
    to scripts/jsconfig.json's include array so tsc --checkJs validates the
    JSDoc @type annotations.
  - Add // @ts-check directive to all 14 .mjs files in the regional-snapshot
    pipeline.
  - Fix 4 type-safety bugs surfaced by enabling type-checking:
      actor-scoring: explicit ActorState[] type on local actors array; cast
        leverage_domains to ActorLeverageDomain[]; typed ActorRole return on
        inferRole.
      evidence-collector: explicit EvidenceItem[] type on local out array.
      scenario-builder: typed HORIZONS as ScenarioHorizon[] and LANE_NAMES
        as ScenarioName[].
      transmission-templates: cast tpl.affectedRegions to RegionId[] when
        building TransmissionPath objects.
  - Pre-existing seed-forecasts.mjs and _r2-storage.mjs errors (46 total)
    are not part of this PR's scope and remain untouched.

Verification
  - npx tsc --noEmit -p scripts/jsconfig.json: 0 errors in regional-snapshot files
  - npm run typecheck:all: clean
  - npm run test:data: 3946/3946 pass
  - tests/regional-snapshot.test.mjs: 50/50 pass
  - End-to-end smoke test: all 8 regions compute clean with confidence=1.0
  - Verified: oref_cluster trigger fires when activeAlertCount > 10
  - Verified: persisted snapshot has no diff field
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant