Skip to content

Conversation

@KaiVandivier
Copy link
Contributor

@KaiVandivier KaiVandivier commented Apr 7, 2025

Part of DHIS2-19412

Adds X-Requested-With = iframe header, but by creating the request in the service worker itself, it also results in Referer = .../service-worker.js, which is convenient.

Tested with these conditions, in v41, v42 in a global shell, and v42 with ?redirect=false for the standalone app:

  1. PWA updates to this version
  2. PWA updates from this version to another version
  3. In plugins (loaded in dashboard)
  4. Regular navigations
  5. Login redirects

Some other details of the request are changed too, as shown by this table, but I think they're okay:
Screenshot 2025-04-07 at 17 16 30

Before:
Screenshot 2025-04-07 at 14 45 07

After:
Screenshot 2025-04-07 at 21 59 06

@sonarqubecloud
Copy link

sonarqubecloud bot commented Apr 7, 2025

@KaiVandivier KaiVandivier changed the title fix: add headers to prevent avoid faulty redirects to global shell [11.x] fix: add headers to avoid faulty redirects to global shell [11.x] Apr 8, 2025
@KaiVandivier KaiVandivier requested a review from amcgee April 8, 2025 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants