feat: proxy /dashboard/api/* through Vercel to dodge third-party cookie blocks (#1303)

Browsers (Safari, Brave, Firefox, increasingly Chrome) refuse to set or
send SameSite=None cookies cross-site. With the frontend on
openswe.vercel.app and the API on *.langgraph.app, the osw_session
cookie from `/auth/callback` was being silently dropped, so every
subsequent /me call returned 401.

Adding a Vercel rewrite makes the API same-origin from the browser's
point of view: the request goes to openswe.vercel.app/dashboard/api/...,
Vercel proxies it to the LangSmith deployment, and the Set-Cookie comes
back attributed to openswe.vercel.app — a first-party cookie that all
browsers honour.

Pair with the matching deployment-side config changes:
  - GitHub App callback URL → https://openswe.vercel.app/dashboard/api/auth/callback
  - DASHBOARD_API_BASE_URL  → https://openswe.vercel.app  (LangSmith env)
  - VITE_DASHBOARD_API_BASE_URL → unset / empty  (Vercel env)
This commit is contained in:
Johannes du Plessis 2026-05-15 12:23:27 -07:00 • committed by GitHub
parent 88856a04fa
commit 19e659f794
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

8
ui/vercel.json Normal file
View file

@ -0,0 +1,8 @@
{
"rewrites": [
{
"source": "/dashboard/api/:path*",
"destination": "https://open-swe-test-3c1f9e43498f5f4ebe6b59a83263e931.us.langgraph.app/dashboard/api/:path*"
}
]
}