Skip to content

Stop www.icemap.app redirecting to https://icemap.app:8080/ - #10

Merged
ralyodio merged 3 commits into
masterfrom
fix/www-redirect
Oct 2, 2026
Merged

ralyodio merged 3 commits into
masterfrom
fix/www-redirect

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

https://www.icemap.app/ answered 301 to https://icemap.app:8080/. The middleware cloned nextUrl and only replaced .host, so the internal port survived. The redirect is now built from x-forwarded-host/Host with the port stripped (apps/web/src/lib/www-redirect.ts, with tests).

🤖 Generated with Claude Code

The middleware cloned request.nextUrl and set .host, which keeps the port
the standalone server listens on. Build the Location from the public host
(x-forwarded-host, then Host) with the port dropped instead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

3 finding(s)

HIGH/CRITICAL: 1 | LOW: 2

Severity Rule Location
HIGH js-ssrf-outbound-request apps/web/src/app/api/media/[...path]/route.ts:28
LOW secret-generic-credential packages/supabase/supabase/config.toml:271
LOW secret-generic-credential packages/supabase/supabase/config.toml:303

Snippets are redacted; ThreatCrush never prints matched credential material.

fast-xml-parser 5.2.5 (via @aws-sdk/xml-builder, GHSA-m7jm-9gc2-mpf2) is
overridden to ^5.3.5 and vitest moves to ^3.2.6 (GHSA-5xrq-8626-4rwp). Both
landed after master's last green audit and were failing this PR's CI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@socket-security

socket-security Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedvitest@​2.1.9 ⏵ 3.2.79899 +747899100

View full report

The override moves fast-xml-parser past 5.3.5, so the hot patch has no
target and socket-patch apply (postinstall) exits 1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ralyodio
ralyodio merged commit 8c02acf into master Oct 2, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant