fix(favorites): route icon img through same-origin proxy, not hotlink

<img src={fav.iconUrl}> hotlinked the external favicon directly; sites
that send Cross-Origin-Resource-Policy: same-origin (e.g. claude.ai)
get blocked by the browser (net::ERR_BLOCKED_BY_RESPONSE.NotSameOrigin),
leaving only the letter fallback. Points src at the new same-origin
/api-proxy/favorites/:id/icon route instead (same pattern already used
for the user avatar image). Render guard and onError fallback unchanged.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-07 15:34:56 +02:00
parent d99253ba79
commit 8fb92a4e2a
@@ -360,7 +360,7 @@ function FavoriteTile({
</span> </span>
{fav.iconUrl && ( {fav.iconUrl && (
<img <img
src={fav.iconUrl} src={`/api-proxy/favorites/${encodeURIComponent(fav.id)}/icon`}
alt="" alt=""
width={20} width={20}
height={20} height={20}