Repository navigation
fix: pin @grafana/faro-web-sdk to 2.11.0 (CORS regression on dev-gcp) - #87
Merged
Merged
Conversation
faro-web-sdk 2.12.0 (via PR grafana/faro-web-sdk#2264, 'make reliable Fetch transport the default') unconditionally sends an Idempotency-Key header on every request, with no opt-out. The Alloy faro.receiver component deployed on nais clusters hardcodes its allowed CORS request headers and does not yet include idempotency-key — that fix (grafana/alloy@a6e19ce) has only shipped in the unreleased v1.20.0-rc.0, not in any stable Alloy release nais currently runs. Because the browser Fetch spec aborts the entire CORS preflight (no Access-Control-Allow-Origin at all) when any requested header isn't in the receiver's allowlist, apps pulling in faro-web-sdk 2.12.0 transitively via @nais/apm's previous ^2.11.0 range see a CORS failure that looks like a missing origin allowlist entry, even though the origin itself is correctly configured. Pin @grafana/faro-web-sdk (dependency) and @grafana/faro-react (devDependency, used for our own test/peer compatibility checks) to the exact 2.11.0 release until nais's Alloy deployment is upgraded past v1.20.0. Un-pin once collector CORS support for Idempotency-Key is confirmed live in all clusters. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
mbolstad
added a commit
to navikt/k9-los-web
that referenced
this pull request
Sep 29, 2026
Samler Dependabot-PR-ene #4385, #4386, #4391, #4395, #4398, #4400, #4403 og #4406, med ett unntak: @grafana/faro-react blir på 2.11.0. @nais/apm er bumpet til 0.7.2, som låser faro-web-sdk til 2.11.0. faro-web-sdk 2.12 sender en Idempotency-Key-header som telemetri- collectoren ikke tillater i CORS, så all telemetri blir blokkert (nais/apm#87). Overrides i pnpm-workspace.yaml låser hele Faro-familien til 2.11.0. Uten dem løftet React-bumpen faro-reacts ^-ranges til 2.12.1, og appen fikk to faro-core-instanser. ApmErrorBoundary og ApmRoutes rapporterte da til en no-op-instans. biome.json peker på schema for 2.5.14.
Merged
sindrerh2
added a commit
that referenced
this pull request
Oct 2, 2026
- **ci(release): sync beta from main (#45)** - **fix(release): restrict beta manual publishing (#47)** - **fix(release): clarify beta release flows (#49)** - **fix(release): target beta branch (#55)** - **fix(release): enable beta prerelease versioning (#58)** - **fix(release): accept valid beta versions (#61)** - **chore: promote beta to main (#75)** - **chore: trigger release-please rerun (#78)** - **chore(main): release apm 0.7.0 (#48)** - **fix(deps): exclude major bumps from npm-all Dependabot group (#81)** - **chore(main): release apm 0.7.1 (#83)** - **chore(deps-dev): bump the npm-all group across 1 directory with 8 updates (#85)** - **chore(deps): bump the faro group across 1 directory with 3 updates (#84)** - **fix: pin @grafana/faro-web-sdk to 2.11.0 (CORS regression on dev-gcp) (#87)** - **chore(main): release apm 0.7.2 (#89)** - **chore(deps): bump the faro group with 3 updates (#91)**
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Multiple teams reported CORS preflight failures on
dev-gcpwhen callinghttps://telemetry.ekstern.dev.nav.no/collect:The origin was correctly allowlisted server-side (verified via direct
curlpreflight tests). The actual cause:
@grafana/faro-web-sdk@2.12.0(pulled intransitively via
@nais/apm's previous^2.11.0range, and directly bumped to^2.12.0onmainby dependabot in #84) unconditionally sends anIdempotency-Keyrequest header on every request as ofgrafana/faro-web-sdk#2264
("make reliable Fetch transport the default"), with no opt-out.
The
Alloyfaro.receivercomponent nais runs (vianais/helm-chartsfeatures/alloy-faro) hardcodes its allowed CORS request headers in Go and doesnot yet include
idempotency-key. That fix(grafana/alloy@a6e19ce, merged
2026-09-09) has only shipped in the unreleased
v1.20.0-rc.0— no stable Alloyrelease contains it yet, including the
1.12.1currently pinned infeatures/alloy-faro/Chart.yaml.Per the Fetch CORS spec,
when any header in
Access-Control-Request-Headersisn't in the receiver'sallowlist, the entire preflight is aborted — no
Access-Control-Allow-Originis set at all, even though the origin itself is valid. This makes a header
allowlist problem look exactly like an origin allowlist problem.
Fix
Pin
@grafana/faro-web-sdk(dependency) and@grafana/faro-react(devDependency, used only for our own peer-compatibility tests) to the exact
2.11.0release — the last version before the unconditionalIdempotency-Keyheader was introduced.
Verification
pnpm test— 244/244 tests passpnpm build— succeedshttps://telemetry.ekstern.dev.nav.no/collectwithAccess-Control-Request-Headers: content-type,idempotency-key,x-faro-session-id→ 204 with no
Access-Control-Allow-Origin. Removingidempotency-keyfromthe request restores the header, confirming this is header- not origin-related.
Follow-up
Un-pin once nais's Alloy deployment is confirmed upgraded past
v1.20.0in allclusters (or a backported patch release ships
idempotency-keysupport earlier).Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com