Follow-up from #13, which added Allow to the 405 on /api/intake/reports but left its sibling untouched.
What
apps/dashboard/server/api/intake/media.post.ts:71 still throws a bare 405:
throw createError({ statusCode: 405, statusMessage: "Method not allowed" })
reports.ts now does this instead:
setResponseHeader(event, "allow", "POST, OPTIONS")
throw createError({
statusCode: 405,
statusMessage: "Method not allowed",
message: "This endpoint only accepts POST from the Repro SDK.",
})
Why it matters
Same reasoning as #13: RFC 9110 §15.5.6 says a 405 MUST carry Allow, and browsers land on these URLs whenever something navigates to them — a pasted link, a link checker, an auth redirect that used the path as a callback target. A bare status line tells the person nothing.
media.post.ts handles OPTIONS the same way reports.ts does, so Allow: POST, OPTIONS is the correct value there too.
Verified
Nitro's error handler (nitropack/dist/runtime/internal/error/prod.mjs) calls setResponseHeaders, which adds headers without clearing ones already set — so a header set before the throw does survive onto the response. #13's CI run confirmed this end-to-end against a live server.
Small and self-contained — good first issue.
Follow-up from #13, which added
Allowto the 405 on/api/intake/reportsbut left its sibling untouched.What
apps/dashboard/server/api/intake/media.post.ts:71still throws a bare 405:reports.tsnow does this instead:Why it matters
Same reasoning as #13: RFC 9110 §15.5.6 says a 405 MUST carry
Allow, and browsers land on these URLs whenever something navigates to them — a pasted link, a link checker, an auth redirect that used the path as a callback target. A bare status line tells the person nothing.media.post.tshandlesOPTIONSthe same wayreports.tsdoes, soAllow: POST, OPTIONSis the correct value there too.Verified
Nitro's error handler (
nitropack/dist/runtime/internal/error/prod.mjs) callssetResponseHeaders, which adds headers without clearing ones already set — so a header set before thethrowdoes survive onto the response. #13's CI run confirmed this end-to-end against a live server.Small and self-contained — good first issue.