feat(server): add environment-aware asset relay#236
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6065c6cfc6
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 20655317ef
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Summary
/_asset-relay/:claimhandling with masking 404ssame-origin-relay-v1; no client URL rewrite, bearer URL, cross-site cookie, or browser redirect fallback is addedBinding design:
/home/adam/.openclaw/reports/app-origin-asset-relay-design-2026-07-21.mdVerification
vp test run packages/contracts/src/assetClaims.test.ts apps/server/src/http.test.ts apps/server/src/assets/AssetAccess.test.ts apps/server/src/server.test.ts— 4 files / 157 tests passedtsgo --noEmitpassedSecurity assertions
Set-Cookie, andLocationare never propagatedAssetClientUpgradeRequiredError