mirror of
https://github.com/open-jarvis/OpenJarvis.git
synced 2026-07-30 02:42:16 +00:00
The SecurityHeadersMiddleware ran before CORSMiddleware (Starlette executes middleware in LIFO order) and added headers to OPTIONS preflight requests. The Content-Security-Policy: default-src 'self' header told the browser to reject cross-origin connections, so fetch() from the Tauri webview (https://tauri.localhost) to the API server (http://127.0.0.1) was blocked — causing "Failed to get response" on every chat message in the desktop app. Two fixes: - Skip security headers on OPTIONS requests so CORS preflight works - Remove Content-Security-Policy from API responses — it is a document-level browser policy irrelevant to JSON API responses and breaks any cross-origin API consumer