Skip to content

intake: media endpoint's 405 is still missing the Allow header #14

Description

@Ripwords

Follow-up from #13, which added Allow to the 405 on /api/intake/reports but left its sibling untouched.

What

apps/dashboard/server/api/intake/media.post.ts:71 still throws a bare 405:

throw createError({ statusCode: 405, statusMessage: "Method not allowed" })

reports.ts now does this instead:

setResponseHeader(event, "allow", "POST, OPTIONS")
throw createError({
  statusCode: 405,
  statusMessage: "Method not allowed",
  message: "This endpoint only accepts POST from the Repro SDK.",
})

Why it matters

Same reasoning as #13: RFC 9110 §15.5.6 says a 405 MUST carry Allow, and browsers land on these URLs whenever something navigates to them — a pasted link, a link checker, an auth redirect that used the path as a callback target. A bare status line tells the person nothing.

media.post.ts handles OPTIONS the same way reports.ts does, so Allow: POST, OPTIONS is the correct value there too.

Verified

Nitro's error handler (nitropack/dist/runtime/internal/error/prod.mjs) calls setResponseHeaders, which adds headers without clearing ones already set — so a header set before the throw does survive onto the response. #13's CI run confirmed this end-to-end against a live server.

Small and self-contained — good first issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions