fix(api-server): resolve CORS headers on session chat stream SSE response (#72892)

The CORS middleware cannot inject headers into StreamResponse after
prepare() flushes them, so streaming endpoints must resolve CORS headers
up front. _handle_session_chat_stream was the only SSE handler that did
not, leaving Access-Control-Allow-Origin absent on the streamed response
even when API_SERVER_CORS_ORIGINS was configured and the origin was
allowed. The sibling endpoints /v1/chat/completions and /v1/responses
already applied the same pattern; this applies it to the session stream.

(cherry picked from commit a2355e12a646a7baf32ff011a8bea358fdccc2c9)
This commit is contained in:
Tranquil-Flow
2026-07-28 00:10:43 +02:00
committed by kshitij
parent 4051be5acc
commit a49fc38b4a
2 changed files with 61 additions and 0 deletions

View File

@@ -3530,6 +3530,12 @@ class APIServerAdapter(OpenAICompatRoutesMixin, BasePlatformAdapter):
headers = {
"Content-Type": "text/event-stream", "Cache-Control": "no-cache",
"X-Accel-Buffering": "no", **self._session_headers(session_id, gateway_session_key)}
# CORS middleware can't inject headers into StreamResponse after
# prepare() flushes them, so resolve CORS headers up front (#72892).
origin = request.headers.get("Origin", "")
cors = self._cors_headers_for_origin(origin) if origin else None
if cors:
headers.update(cors)
response = web.StreamResponse(status=200, headers=headers)
await response.prepare(request)
try: