Files
OpenHands/__tests__/api/runtime-service
Calvin Smithandopenhands d823e0137d fix: preserve target protocol in buildHttpBaseUrl (#1297)
* fix: preserve target protocol in buildHttpBaseUrl

buildHttpBaseUrl() used window.location.protocol to determine the scheme
for conversation-specific HTTP requests, ignoring the conversation URL's
own protocol. When Canvas runs on http://localhost and the backend is an
HTTPS remote (e.g. *.modal.run), conversation-specific requests
(events/search, bash, git, workspace-session) were rewritten to http://.
The remote returns a 308 HTTP→HTTPS redirect, which browsers refuse to
follow on CORS preflight (OPTIONS) requests, breaking all non-simple
requests while global API calls (settings, conversations/search) worked
fine since they use backend.host directly.

Apply the same pageIsSecure || targetIsSecure pattern already used by
buildBashWebSocketUrl and buildWebSocketUrl in the same file.

Co-authored-by: openhands <openhands@all-hands.dev>

* test: update hostOverride assertions to expect https:// for https targets

Align test expectations with the buildHttpBaseUrl fix — conversation URLs
with an https:// scheme should produce https:// base URLs, not http://.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-11 16:10:11 -06:00
..