Include the desktop origin in generated CORS settings
The backend only allows app://j621 through CORS_ALLOWED_ORIGINS, so gen_env.sh now always writes that origin (plus the split-deploy frontend when one is given) and --update keeps hand-added origins instead of overwriting the list.
This commit is contained in:
+4
-4
@@ -30,10 +30,10 @@ ALLOWED_HOSTS=j621.rainbow-herring.ts.net,localhost,127.0.0.1
|
||||
# ---------------------------------------------------------------------------
|
||||
# Cross-origin access (needed for the separate frontend + backend deploys)
|
||||
# ---------------------------------------------------------------------------
|
||||
# The origin the SPA is served from, e.g. https://j621-frontend.<tailnet>.ts.net
|
||||
# The desktop app (desktop/) is served from app://j621, so add that origin too
|
||||
# when it should reach this backend:
|
||||
# CORS_ALLOWED_ORIGINS=https://j621-frontend.<tailnet>.ts.net,app://j621
|
||||
# The origin the SPA is served from for split deploys, e.g.
|
||||
# https://j621-frontend.<tailnet>.ts.net. gen_env.sh writes this plus the
|
||||
# desktop shell's app://j621 origin into the line below (and keeps existing
|
||||
# entries on --update).
|
||||
# CORS_ALLOWED_ORIGINS=
|
||||
# CSRF_TRUSTED_ORIGINS=
|
||||
|
||||
|
||||
+3
-3
@@ -93,9 +93,9 @@ The SPA asks where the backend is (`/setup`) in production builds:
|
||||
and give the backend `CORS_ALLOWED_ORIGINS=https://<frontend-host>.<tailnet>.ts.net`
|
||||
(plus `CSRF_TRUSTED_ORIGINS` for the admin).
|
||||
- **Desktop app** — the Electron shell (`desktop/`) is served from the
|
||||
`app://j621` origin, so it needs that entry too:
|
||||
`CORS_ALLOWED_ORIGINS=...,app://j621`. The shell's setup screen prints the
|
||||
exact origin when the connection test fails.
|
||||
`app://j621` origin, which `gen_env.sh` includes in `CORS_ALLOWED_ORIGINS`
|
||||
automatically (add it by hand if you wrote `.env` yourself). The shell's
|
||||
setup screen prints the exact origin when the connection test fails.
|
||||
- Without a backend at all, choose **"Continue without a backend"** to run in
|
||||
local mode (e621 browsing only).
|
||||
|
||||
|
||||
+20
-1
@@ -86,7 +86,26 @@ FQDN="${FQDN:-$DEFAULT_FQDN}"
|
||||
# Derive the rest from the tailnet hostname.
|
||||
TS_HOSTNAME="${FQDN%%.*}"
|
||||
ALLOWED_HOSTS="$FQDN,localhost,127.0.0.1"
|
||||
CORS_ALLOWED_ORIGINS="${FRONTEND:+https://$FRONTEND}"
|
||||
|
||||
# Cross-origin access: the optional split-deploy frontend plus the desktop
|
||||
# shell, which is always a different origin from the backend. On --update the
|
||||
# existing list is kept, so hand-added origins survive.
|
||||
CORS_ALLOWED_ORIGINS=""
|
||||
add_origin() {
|
||||
[ -n "${1:-}" ] || return 0
|
||||
case ",$CORS_ALLOWED_ORIGINS," in
|
||||
*",$1,"*) ;;
|
||||
*) CORS_ALLOWED_ORIGINS="${CORS_ALLOWED_ORIGINS:+$CORS_ALLOWED_ORIGINS,}$1" ;;
|
||||
esac
|
||||
}
|
||||
if [ "$UPDATE" -eq 1 ]; then
|
||||
while IFS= read -r origin; do
|
||||
add_origin "$origin"
|
||||
done < <(existing CORS_ALLOWED_ORIGINS | tr ',' '\n')
|
||||
fi
|
||||
[ -n "$FRONTEND" ] && add_origin "https://$FRONTEND"
|
||||
add_origin "app://j621"
|
||||
|
||||
CSRF_TRUSTED_ORIGINS="${FRONTEND:+https://$FRONTEND}"
|
||||
|
||||
J621_SECRET_KEY="$SECRET_KEY" \
|
||||
|
||||
Reference in New Issue
Block a user