This is an automated email from the ASF dual-hosted git repository.

github-merge-queue[bot] pushed a commit to branch 
gh-readonly-queue/release/v1.3/pr-8623-0f3192ea416e151ef73682e9aee33c878f79096f
in repository https://gitbox.apache.org/repos/asf/texera.git

commit 3e800323d5be1a4b8fd5079ce8d5cb33fbfe22fe
Author: Meng Wang <[email protected]>
AuthorDate: Mon Sep 21 20:08:01 2026 +0000

    fix(deploy, v1.3): enable CORS on RustFS so browsers can fetch presigned 
URLs (#8623)
    
    ### What changes were proposed in this PR?
    
    Backport of #8562 to `release/v1.3`: a clean cherry-pick of its squash
    commit, no adaptations — five added lines across the single-node compose
    file, the dev compose file and the Helm chart's `extraEnv`.
    
    This branch needs it because #8550 already made RustFS the default
    object store here. RustFS sends no CORS headers unless
    `RUSTFS_CORS_ALLOWED_ORIGINS` is set (its reflective default was removed
    as CVE-2026-46685), while MinIO sent them by default — so without this
    change a v1.3 deployment renders no dataset file preview: the browser's
    cross-origin fetch of the presigned URL is blocked and the preview stays
    in its loading state.
    
    Opened manually by the v1.3 release manager: the automated fast path
    cherry-picked this cleanly and then pushed it straight to
    `release/v1.3`, where the Merge Queue ruleset rejected the push
    (`GH013`, [run
    35305278774](https://github.com/apache/texera/actions/runs/35305278774)).
    The Actions-app bypass meant to unblock that path (#8379) was never
    created — asfyaml rejects an `Integration` bypass actor — and the
    failing job's notification 403s for want of `pull-requests: write`, so
    the loss left neither a backport PR nor a comment on #8562. The
    `release/v1.2` backport did get a PR (#8585, merged) only because it
    took the other code path. See #8377.
    
    Source: af6e0fdd96f44c1d575278b9fd12ed61ce6a8640
    
    ### Any related issues, documentation, discussions?
    
    Backport of #8562. Originally linked #8557.
    
    ### How was this PR tested?
    
    The change is identical to #8562 (configuration only, no application
    code); the backport tree is verified byte-identical to cherry-picking
    the squash commit onto `release/v1.3`. Release-branch CI runs the full
    matrix on this PR, including the integration jobs that provision RustFS.
    
    ### Was this PR authored or co-authored using generative AI tooling?
    
    Yes. Generated-by: Claude Code (claude-opus-5)
    
    Co-authored-by: Xuan Gu <[email protected]>
    Co-authored-by: Claude Fable 5 <[email protected]>
---
 bin/k8s/values.yaml                                | 3 +++
 bin/single-node/docker-compose.yml                 | 1 +
 file-service/src/main/resources/docker-compose.yml | 1 +
 3 files changed, 5 insertions(+)

diff --git a/bin/k8s/values.yaml b/bin/k8s/values.yaml
index 11b102b728..f88d5acd14 100644
--- a/bin/k8s/values.yaml
+++ b/bin/k8s/values.yaml
@@ -111,6 +111,9 @@ rustfs:
     rustfs:
       access_key: texera_rustfs
       secret_key: password
+  extraEnv:
+    - name: RUSTFS_CORS_ALLOWED_ORIGINS
+      value: "*"
   config:
     rustfs:
       # Must match storage.s3.region: the region is part of the SigV4 scope.
diff --git a/bin/single-node/docker-compose.yml 
b/bin/single-node/docker-compose.yml
index f604db653a..d09cbc09a3 100644
--- a/bin/single-node/docker-compose.yml
+++ b/bin/single-node/docker-compose.yml
@@ -29,6 +29,7 @@ services:
     environment:
       - RUSTFS_ACCESS_KEY=${STORAGE_S3_AUTH_USERNAME}
       - RUSTFS_SECRET_KEY=${STORAGE_S3_AUTH_PASSWORD}
+      - RUSTFS_CORS_ALLOWED_ORIGINS=*
       # Must match STORAGE_S3_REGION: the region is part of the SigV4 scope, 
and
       # LakeFS sends its blockstore region on every request.
       - RUSTFS_REGION=${STORAGE_S3_REGION}
diff --git a/file-service/src/main/resources/docker-compose.yml 
b/file-service/src/main/resources/docker-compose.yml
index 95088150b1..98cef98029 100644
--- a/file-service/src/main/resources/docker-compose.yml
+++ b/file-service/src/main/resources/docker-compose.yml
@@ -27,6 +27,7 @@ services:
     environment:
       - RUSTFS_ACCESS_KEY=texera_rustfs
       - RUSTFS_SECRET_KEY=password
+      - RUSTFS_CORS_ALLOWED_ORIGINS=*
       # Must match the region the AWS SDK signs with: it is part of the SigV4 
scope.
       - RUSTFS_REGION=us-west-2
       - RUSTFS_CONSOLE_ENABLE=true

Reply via email to