diff --git a/apps/desktop/electron/primary-backend-startup.test.ts b/apps/desktop/electron/primary-backend-startup.test.ts index de94ddee78..dc5f208245 100644 --- a/apps/desktop/electron/primary-backend-startup.test.ts +++ b/apps/desktop/electron/primary-backend-startup.test.ts @@ -50,6 +50,30 @@ test('primary remote descriptor preserves a resolved registry connection id', () assert.equal(connection.isFullscreen, false) }) +test('primary remote descriptor preserves the gateway extra headers for REST calls', () => { + // Chat and the Test button carry the headers via the exact-URL WS store, but + // fetchJsonForBackend reads descriptor.headers — dropping them here made every + // Settings/session-history call hit an access proxy unauthenticated (#112072). + const headers = { 'CF-Access-Client-Id': 'client-id', 'CF-Access-Client-Secret': 'client-secret' } + + const connection = createPrimaryRemoteConnection( + { + authMode: 'token', + baseUrl: 'https://gateway.example.com', + connectionId: 'gateway', + headers, + remoteKind: 'url', + source: 'settings', + token: 'secret', + wsUrl: 'wss://gateway.example.com/api/ws?token=secret' + }, + [], + {} + ) + + assert.deepEqual(connection.headers, headers) +}) + test('primary remote descriptor preserves the effective SSH dialing identity', () => { const ssh = { effectiveConfigFingerprint: 'effective-config', diff --git a/apps/desktop/electron/primary-backend-startup.ts b/apps/desktop/electron/primary-backend-startup.ts index 37996bcb9d..e319b9b240 100644 --- a/apps/desktop/electron/primary-backend-startup.ts +++ b/apps/desktop/electron/primary-backend-startup.ts @@ -19,6 +19,7 @@ interface ResolvedPrimaryRemote { authMode?: 'oauth' | 'token' baseUrl: string connectionId?: string + headers?: Record remoteHermesVersion?: string remoteHost?: string remoteKind?: 'cloud' | 'ssh' | 'url' @@ -56,6 +57,9 @@ export function createPrimaryRemoteConnection( remoteHermesVersion: remote.remoteHermesVersion, ...(remote.connectionId ? { connectionId: remote.connectionId } : {}), ...(remote.ssh ? { ssh: remote.ssh } : {}), + // fetchJsonForBackend reads descriptor.headers for every REST call; the + // WebSocket header store is keyed by exact URL and cannot stand in for it. + headers: remote.headers, token: remote.token, wsUrl: remote.wsUrl, logs,