diff --git a/deploy/.env.example b/deploy/.env.example index 95958b7..17fc069 100644 --- a/deploy/.env.example +++ b/deploy/.env.example @@ -30,10 +30,10 @@ ALLOWED_HOSTS=j621.rainbow-herring.ts.net,localhost,127.0.0.1 # --------------------------------------------------------------------------- # Cross-origin access (needed for the separate frontend + backend deploys) # --------------------------------------------------------------------------- -# The origin the SPA is served from, e.g. https://j621-frontend..ts.net -# The desktop app (desktop/) is served from app://j621, so add that origin too -# when it should reach this backend: -# CORS_ALLOWED_ORIGINS=https://j621-frontend..ts.net,app://j621 +# The origin the SPA is served from for split deploys, e.g. +# https://j621-frontend..ts.net. gen_env.sh writes this plus the +# desktop shell's app://j621 origin into the line below (and keeps existing +# entries on --update). # CORS_ALLOWED_ORIGINS= # CSRF_TRUSTED_ORIGINS= diff --git a/deploy/README.md b/deploy/README.md index b82741e..a349f4b 100644 --- a/deploy/README.md +++ b/deploy/README.md @@ -93,9 +93,9 @@ The SPA asks where the backend is (`/setup`) in production builds: and give the backend `CORS_ALLOWED_ORIGINS=https://..ts.net` (plus `CSRF_TRUSTED_ORIGINS` for the admin). - **Desktop app** — the Electron shell (`desktop/`) is served from the - `app://j621` origin, so it needs that entry too: - `CORS_ALLOWED_ORIGINS=...,app://j621`. The shell's setup screen prints the - exact origin when the connection test fails. + `app://j621` origin, which `gen_env.sh` includes in `CORS_ALLOWED_ORIGINS` + automatically (add it by hand if you wrote `.env` yourself). The shell's + setup screen prints the exact origin when the connection test fails. - Without a backend at all, choose **"Continue without a backend"** to run in local mode (e621 browsing only). diff --git a/deploy/gen_env.sh b/deploy/gen_env.sh index 47b5b0c..7feeefb 100755 --- a/deploy/gen_env.sh +++ b/deploy/gen_env.sh @@ -86,7 +86,26 @@ FQDN="${FQDN:-$DEFAULT_FQDN}" # Derive the rest from the tailnet hostname. TS_HOSTNAME="${FQDN%%.*}" ALLOWED_HOSTS="$FQDN,localhost,127.0.0.1" -CORS_ALLOWED_ORIGINS="${FRONTEND:+https://$FRONTEND}" + +# Cross-origin access: the optional split-deploy frontend plus the desktop +# shell, which is always a different origin from the backend. On --update the +# existing list is kept, so hand-added origins survive. +CORS_ALLOWED_ORIGINS="" +add_origin() { + [ -n "${1:-}" ] || return 0 + case ",$CORS_ALLOWED_ORIGINS," in + *",$1,"*) ;; + *) CORS_ALLOWED_ORIGINS="${CORS_ALLOWED_ORIGINS:+$CORS_ALLOWED_ORIGINS,}$1" ;; + esac +} +if [ "$UPDATE" -eq 1 ]; then + while IFS= read -r origin; do + add_origin "$origin" + done < <(existing CORS_ALLOWED_ORIGINS | tr ',' '\n') +fi +[ -n "$FRONTEND" ] && add_origin "https://$FRONTEND" +add_origin "app://j621" + CSRF_TRUSTED_ORIGINS="${FRONTEND:+https://$FRONTEND}" J621_SECRET_KEY="$SECRET_KEY" \