fix(extensions): show package icons again in the desktop and dev UI
Extension rail icons came up empty. The rail draws a package SVG as a CSS mask, which the browser fetches with CORS from the app UI's origin (openchamber-ui:// in the desktop, localhost in dev). The guest file route set Access-Control-Allow-Origin: null for the sandboxed frame's fonts and overwrote the answer the server's CORS layer had already given the UI, so every mask was refused. The route now sets null only when no origin was allowed before it: the frame still reads its own files, and the UI keeps its own answer. Tested with the guests suite, including a case for a UI request and a frame request; the old line turns that case red.
B
Bohdan Triapitsyn committed
8aebeaa777277811341d3a63a8a0b4ee3172fcf2
Parent: c1cd3e5