mirror of
https://github.com/OpenHands/OpenHands.git
synced 2026-10-07 16:58:14 +08:00
* fix: preserve target protocol in buildHttpBaseUrl buildHttpBaseUrl() used window.location.protocol to determine the scheme for conversation-specific HTTP requests, ignoring the conversation URL's own protocol. When Canvas runs on http://localhost and the backend is an HTTPS remote (e.g. *.modal.run), conversation-specific requests (events/search, bash, git, workspace-session) were rewritten to http://. The remote returns a 308 HTTP→HTTPS redirect, which browsers refuse to follow on CORS preflight (OPTIONS) requests, breaking all non-simple requests while global API calls (settings, conversations/search) worked fine since they use backend.host directly. Apply the same pageIsSecure || targetIsSecure pattern already used by buildBashWebSocketUrl and buildWebSocketUrl in the same file. Co-authored-by: openhands <openhands@all-hands.dev> * test: update hostOverride assertions to expect https:// for https targets Align test expectations with the buildHttpBaseUrl fix — conversation URLs with an https:// scheme should produce https:// base URLs, not http://. Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev>