Skip to content

fix(console): add cors to zen responses - #42101

Closed
zcxGGmu wants to merge 1 commit into
anomalyco:devfrom
zcxGGmu:zen-cors-headers
Closed

zcxGGmu wants to merge 1 commit into
anomalyco:devfrom
zcxGGmu:zen-cors-headers

Conversation

@zcxGGmu

@zcxGGmu zcxGGmu commented Aug 12, 2026

Copy link
Copy Markdown

Issue for this PR

Closes #41224

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

Adds CORS headers to actual Zen model-list responses, not only OPTIONS preflight responses. The shared helper is also used by the main Zen chat handler response headers so normal GET/POST responses include Access-Control-Allow-Origin as browsers require after a successful preflight.

This keeps the existing permissive preflight policy (*, GET, POST, OPTIONS, Content-Type, Authorization) and applies it to actual API responses.

How did you verify your code works?

  • cd packages/console/app && bun test test/zenCors.test.ts --timeout 30000
  • cd packages/console/app && bun run typecheck
  • bunx oxlint packages/console/app/src/routes/zen/util/modelsHandler.ts packages/console/app/src/routes/zen/util/handler.ts packages/console/app/test/zenCors.test.ts
  • git diff --check

Screenshots / recordings

N/A; this is a response-header fix.

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

@github-actions

Copy link
Copy Markdown
Contributor

The following comment was made by an LLM, it may be inaccurate:

Potential Duplicate Found

PR #37932: fix(console): add CORS headers and OPTIONS preflight to Zen/Go API endpoints
#37932

Why it might be related:

You should verify if #37932 is already merged or if it addresses the same issue (#41224). If it's closed/merged without fixing the issue, that explains why the current PR was needed.

@github-actions

Copy link
Copy Markdown
Contributor

Automated PR Cleanup

Thank you for contributing to opencode.

Due to the high volume of PRs from users and AI agents, we periodically close older PRs using automated criteria so maintainers can focus review time on the most active and community-supported contributions.

This PR was closed because it matched the following cleanup criteria:

  • The PR was created more than 1 month ago
  • The PR had fewer than 2 positive reactions
  • Positive reactions are counted as thumbs-up, heart, celebration, or rocket reactions on the PR

PRs created within the last month are not affected by this cleanup.

If you believe this PR was closed incorrectly, or if you are still actively working on it, please leave a comment explaining why it should be reopened. A maintainer can review and reopen it if appropriate.

Thanks again for taking the time to contribute.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Zen/Go API endpoints missing Access-Control-Allow-Origin on actual responses (CORS fails for browser-based clients)

2 participants