From 30d6e0a5df0bba41eb191968e76fabf9e7e0b392 Mon Sep 17 00:00:00 2001 From: Schalli Date: Tue, 7 Jul 2026 15:39:02 +0200 Subject: [PATCH] fix(favorites): use browser-like Accept header for icon byte-fetch A bare "image/*" Accept paired with the tessera/1.0 User-Agent tripped Cloudflare bot mitigation on some sites -- caught live testing against chatgpt.com/favicon.ico, which returned 403 with this combo but 200 with a realistic browser-style image Accept list. Isolated via direct fetch comparison inside the API container before landing the fix. Co-Authored-By: Claude Sonnet 5 --- apps/api/src/favorites/icon-discovery.service.ts | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/apps/api/src/favorites/icon-discovery.service.ts b/apps/api/src/favorites/icon-discovery.service.ts index 1d741dd..83ecff3 100644 --- a/apps/api/src/favorites/icon-discovery.service.ts +++ b/apps/api/src/favorites/icon-discovery.service.ts @@ -330,7 +330,11 @@ export class IconDiscoveryService { const url = new URL(iconUrl); const result = await fetchWithRedirectGuard(url, { - accept: 'image/*', + // A bare "image/*" Accept header (paired with our non-browser + // User-Agent) trips bot-mitigation WAFs on some sites (observed: + // chatgpt.com/favicon.ico returns 403 with this combo) — a realistic + // browser-style image Accept list avoids that false positive. + accept: 'image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8', timeoutMs: ICON_FETCH_TIMEOUT_MS, });