mirror of
https://github.com/HeyPuter/puter.git
synced 2026-10-02 09:58:16 +00:00
Browser uploads (Dev Center deploy, puter.fs.upload) PUT file bytes directly to presigned URLs on the public S3 endpoint. That cross-origin PUT is preflighted, and the bucket had no CORS rules, so RustFS answered without Access-Control-Allow-Origin and the browser blocked the upload. s3-init now runs put-bucket-cors on every boot after ensuring the bucket exists (idempotent). Origins are open because the presigned URL is the credential and the SDK sends no cookies. Document how to re-run and verify in doc/self-hosting.md.