Skip to content

fix(tanstackstart-react): Reject non-POST requests to the managed tunnel route - #24615

Merged
Lms24 merged 1 commit into
developfrom
fix/tanstackstart-tunnel-route-non-post
Sep 23, 2026
Merged

Lms24 merged 1 commit into
developfrom
fix/tanstackstart-tunnel-route-non-post

Conversation

@Lms24

@Lms24 Lms24 commented Sep 23, 2026

Copy link
Copy Markdown
Member

This PR fixes a tunnel route bug where a non-POST (or rather GET) request to the route would cause TSS to render a page rather than reject the request on that route. This adds an ANY handler that returns 405 with Allow: POST. POST still takes precedence, so real tunnel requests are unchanged.

Fixes #24605

…nel route

The managed tunnel route only defined a POST handler, so other methods fell through to SSR-rendering the app, running root route loaders. Add an ANY handler that returns 405.

Fixes #24605

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

size-limit report 📦

⚠️ Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

Path Size % Change Change
@sentry/browser 29.23 kB - -
@sentry/browser - with treeshaking flags 27.5 kB - -
@sentry/browser - with treeshaking flags tracing without tracing 27.4 kB - -
@sentry/browser (incl. Tracing) 51.16 kB - -
@sentry/browser (incl. Tracing + Span Streaming) 51.17 kB - -
@sentry/browser (incl. Tracing, Profiling) 54.16 kB - -
@sentry/browser (incl. Tracing, Replay) 90.75 kB - -
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 79.85 kB - -
@sentry/browser (incl. Tracing, Replay with Canvas) 95.45 kB - -
@sentry/browser (incl. Tracing, Replay, Feedback) 108.42 kB - -
@sentry/browser (incl. Feedback) 46.76 kB - -
@sentry/browser (incl. sendFeedback) 34.29 kB - -
@sentry/browser (incl. FeedbackAsync) 39.39 kB - -
@sentry/browser (incl. Metrics) 30.25 kB - -
@sentry/browser (incl. Logs) 30.5 kB - -
@sentry/browser (incl. Metrics & Logs) 31.17 kB - -
@sentry/react 30.98 kB - -
@sentry/react (incl. Tracing) 53.44 kB - -
@sentry/vue 36.72 kB - -
@sentry/vue (incl. Tracing) 53.69 kB - -
@sentry/svelte 29.25 kB - -
CDN Bundle 30.93 kB - -
CDN Bundle (incl. Tracing) 51.69 kB - -
CDN Bundle (incl. Logs, Metrics) 33.19 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 53.66 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 73.92 kB - -
CDN Bundle (incl. Tracing, Replay) 89.27 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 91.23 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 95.43 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 97.4 kB - -
CDN Bundle - uncompressed 91.4 kB - -
CDN Bundle (incl. Tracing) - uncompressed 153.76 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 97.97 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 159.72 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 227.54 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 273.5 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 279.43 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 287.2 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 293.13 kB - -
@sentry/nextjs (client) 55.78 kB - -
@sentry/sveltekit (client) 51.59 kB - -
@sentry/core/server 39.92 kB - -
@sentry/core/browser 13.63 kB - -
@sentry/node 133.88 kB +0.02% +17 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection) 82.4 kB - -
@sentry/node - without tracing 90.4 kB +0.01% +8 B 🔺
@sentry/node - without channel injection 112.42 kB +0.02% +21 B 🔺
@sentry/aws-serverless 98.71 kB +0.03% +22 B 🔺
@sentry/cloudflare (withSentry) - minified 206.34 kB - -
@sentry/cloudflare (withSentry) 513.42 kB - -

View base workflow run

@Lms24
Lms24 marked this pull request as ready for review September 23, 2026 07:29
@Lms24
Lms24 requested a review from a team as a code owner September 23, 2026 07:29
@Lms24
Lms24 requested review from nicohrubec and s1gr1d and removed request for a team September 23, 2026 07:29
@Lms24 Lms24 self-assigned this Sep 23, 2026
@Lms24
Lms24 requested a review from chargome September 23, 2026 07:29
@Lms24
Lms24 merged commit 84027a1 into develop Sep 23, 2026
49 checks passed
@Lms24
Lms24 deleted the fix/tanstackstart-tunnel-route-non-post branch September 23, 2026 07:38
Lms24 added a commit that referenced this pull request Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Tanstack start vite plugin tunnelRoute option mounts tunnel as a child route, which runs root data loaders on requests

2 participants