From 19e659f794d7e046489325f8696a24ec0d8a7a2c Mon Sep 17 00:00:00 2001 From: Johannes du Plessis Date: Fri, 15 May 2026 12:23:27 -0700 Subject: [PATCH] feat: proxy /dashboard/api/* through Vercel to dodge third-party cookie blocks (#1303) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Browsers (Safari, Brave, Firefox, increasingly Chrome) refuse to set or send SameSite=None cookies cross-site. With the frontend on openswe.vercel.app and the API on *.langgraph.app, the osw_session cookie from `/auth/callback` was being silently dropped, so every subsequent /me call returned 401. Adding a Vercel rewrite makes the API same-origin from the browser's point of view: the request goes to openswe.vercel.app/dashboard/api/..., Vercel proxies it to the LangSmith deployment, and the Set-Cookie comes back attributed to openswe.vercel.app — a first-party cookie that all browsers honour. Pair with the matching deployment-side config changes: - GitHub App callback URL → https://openswe.vercel.app/dashboard/api/auth/callback - DASHBOARD_API_BASE_URL → https://openswe.vercel.app (LangSmith env) - VITE_DASHBOARD_API_BASE_URL → unset / empty (Vercel env) --- ui/vercel.json | 8 ++++++++ 1 file changed, 8 insertions(+) create mode 100644 ui/vercel.json diff --git a/ui/vercel.json b/ui/vercel.json new file mode 100644 index 00000000..57d011cb --- /dev/null +++ b/ui/vercel.json @@ -0,0 +1,8 @@ +{ + "rewrites": [ + { + "source": "/dashboard/api/:path*", + "destination": "https://open-swe-test-3c1f9e43498f5f4ebe6b59a83263e931.us.langgraph.app/dashboard/api/:path*" + } + ] +}