AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Safari CORS Preflight Failure Due To Missing Access-Control-Allow-Headers For Supabase-Js Custom Headers

Safari intermittently fails to fetch Supabase API endpoints because the CORS preflight response does not include the 'accept-profile' header (and possibly other custom headers) in Access-Control-Allow-Headers, causing the browser to reject the request with 'access control checks' errors.

highConfidence 85%SupabaseAffected V@supabase/supabase-Js@2.39.0

Origin Analysis

Supabase API gateway (Kong) CORS configuration does not explicitly allow all custom headers sent by @supabase/supabase-js v2.39.0, notably 'accept-profile'. Safari's WebKit enforces CORS header whitelisting more strictly than Chrome and rejects the preflight when required headers are absent, leading to intermittent failures.
Use Safari 17.2 or later, make any Supabase API call (e.g., supabase.from('orders').select()) from a cross-origin frontend. Observe the browser console showing 'Fetch API cannot load ... due to access control checks'. Inspect the OPTIONS preflight response: it lacks Access-Control-Allow-Headers for 'accept-profile'.

Fixing Code Block

Edge Case Audit

This change only addresses the specific missing header. If future supabase-js versions introduce additional custom headers, they must be added to the list. Avoid using wildcard '*' for Access-Control-Allow-Headers as older Safari versions may not support it. Test the change in multiple browsers and versions. To rollback, revert the CORS plugin configuration to its previous state. Ensure no security impact by limiting allowed headers to those actually used.

Ecosystem Topology