The GitHub Actions job "Release Auditing" on 
texera.git/backport/8562-enable-cors-on-rustfs-so-browsers-can-fe-v1.2 has 
succeeded.
Run started by GitHub user github-actions[bot] (triggered by xuang7).

Head commit for run:
268bce774432f7d0f29a109e03048cf6a1e74f2d / Xuan Gu 
<[email protected]>
fix(deploy): enable CORS on RustFS so browsers can fetch presigned URLs (#8562)

### What changes were proposed in this PR?

Set `RUSTFS_CORS_ALLOWED_ORIGINS=*` on the rustfs service (single-node
compose, K8s chart via `extraEnv`, dev compose).

The dataset file preview fetches presigned URLs directly from the
browser, which is cross-origin. MinIO sent CORS headers by default;
RustFS sends none unless this variable is set (the old reflective
default was removed as CVE-2026-46685), so the preview shows a loading
state and does not render the content. Wildcard mode never allows
credentialed requests, and presigned requests carry no cookies, so this
restores MinIO's behavior without loosening anything; deployments that
want an allow-list can override it with their GUI origin.

### Any related issues, documentation, discussions?

Fixes #8557.

### How was this PR tested?

Tested on single-node deployment.

### Was this PR authored or co-authored using generative AI tooling?

Generated-by: Claude Fable 5 (Claude Code)

(backported from commit af6e0fdd96f44c1d575278b9fd12ed61ce6a8640)

Co-authored-by: Claude Fable 5 <[email protected]>

Report URL: https://github.com/apache/texera/actions/runs/35305314660

With regards,
GitHub Actions via GitBox

Reply via email to