From 325bce04137dfc45ef2e8700c7b92c5768dd5b1a Mon Sep 17 00:00:00 2001 From: hansjone Date: Thu, 30 Jul 2026 02:34:25 +0000 Subject: [PATCH] fix(topology): send auth token on discover stream requests The SSE discover endpoint used raw fetch without Authorization, so login sessions got unauthorized after auth was enabled. Co-authored-by: Cursor --- web/src/services/api.ts | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/web/src/services/api.ts b/web/src/services/api.ts index 57fc327..701ad64 100644 --- a/web/src/services/api.ts +++ b/web/src/services/api.ts @@ -563,15 +563,20 @@ export async function discoverTopologyNeighborsStream( handlers: TopologyDiscoverStreamHandlers, signal?: AbortSignal, ): Promise { - const res = await fetch(`/v1/topology/maps/${encodeURIComponent(mapId)}/discover/stream`, { + const path = `/v1/topology/maps/${encodeURIComponent(mapId)}/discover/stream`; + const res = await fetch(path, { method: "POST", - headers: { + headers: authHeaders({ accept: "text/event-stream", "content-type": "application/json", - }, + }), body: JSON.stringify(body || {}), signal, }); + if (res.status === 401) { + handleUnauthorized(path); + throw new Error("unauthorized"); + } if (!res.ok) { const text = await res.text().catch(() => ""); throw new Error(text || `discover_stream_failed:${res.status}`);