fix: cut machine-path egress (browser headers, 204 heartbeat) - #219
Merged
Merged
Conversation
CSP, X-Frame-Options, X-XSS-Protection, Referrer-Policy and HSTS were sent on every appliance, feed and legacy-forwarding response: ~650 bytes of headers against a 175-byte heartbeat body, on ~2M responses a day, all billed as Render egress. Each machine location now declares its own add_header (nosniff only), which stops nginx from inheriting the browser block. Frontend and /backend/api keep the full set.
The 200 JSON reply (code, message, system_key, timestamp) was read by no client: ns8-core and ns-plug send-heartbeat both discard the body and only check for a 2xx. Dropping it saves ~245 bytes on each of the ~1.7M daily heartbeats. Docs and OpenAPI now tell integrators to rely on the status code only.
edospadoni
temporarily deployed
to
proxy-machine-egress - my-backend-qa PR #219
October 5, 2026 13:18 — with
Render
Destroyed
edospadoni
temporarily deployed
to
proxy-machine-egress - my-collect-qa PR #219
October 5, 2026 13:18 — with
Render
Destroyed
Contributor
|
🔗 Redirect URIs Added to Logto The following redirect URIs have been automatically added to the Logto application configuration: Redirect URIs:
Post-logout redirect URIs:
These will be automatically removed when the PR is closed or merged. |
Contributor
🚨 Breaking my.nethesis.it API change detectedStructural change detailsModified (1)
Powered by Bump.sh |
The legacy forwards (/api, /isa, /proxy, /auth) are same-origin with the SPA, whose Logto tokens live in browser storage, and /proxy already answers some errors as text/html. Dropping CSP there removed the safety net against any HTML the legacy stack might reflect. default-src 'none'; frame-ancestors 'none' restores it, stricter than the dashboard policy, for ~70 bytes instead of ~500.
edospadoni
temporarily deployed
to
proxy-machine-egress - my-proxy-qa PR #219
October 5, 2026 13:38 — with
Render
Destroyed
Contributor
|
🗑️ Redirect URIs Removed from Logto The following redirect URIs have been automatically removed from the Logto application configuration: Redirect URIs:
Post-logout redirect URIs:
Cleanup completed for PR #219. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Changes
add_header, so they no longer inherit the dashboard set (CSP/XFO/XSS/Referrer/HSTS); they keepnosniff+ a deny-all CSP (default-src 'none'; frame-ancestors 'none'), stricter than before for any HTML the same-origin legacy stack might return; frontend and/backend/apiunchanged204 No Content; docs + OpenAPI updatedCompatibility
send-heartbeatdiscard the body and accept any 2xx (checked on a cutover NS8 node and a NethSecurity 8.8.0 unit)Expected: proxy ~2.45 → ~0.95 GB/day (−61%), heartbeat reply ~1075 → ~240 B
Review focus