fix(favorites): use browser-like Accept header for icon byte-fetch

A bare "image/*" Accept paired with the tessera/1.0 User-Agent tripped
Cloudflare bot mitigation on some sites -- caught live testing against
chatgpt.com/favicon.ico, which returned 403 with this combo but 200
with a realistic browser-style image Accept list. Isolated via direct
fetch comparison inside the API container before landing the fix.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-07 15:39:02 +02:00
parent 8fb92a4e2a
commit 30d6e0a5df
@@ -330,7 +330,11 @@ export class IconDiscoveryService {
const url = new URL(iconUrl);
const result = await fetchWithRedirectGuard(url, {
accept: 'image/*',
// A bare "image/*" Accept header (paired with our non-browser
// User-Agent) trips bot-mitigation WAFs on some sites (observed:
// chatgpt.com/favicon.ico returns 403 with this combo) — a realistic
// browser-style image Accept list avoids that false positive.
accept: 'image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8',
timeoutMs: ICON_FETCH_TIMEOUT_MS,
});