Include the desktop origin in generated CORS settings

The backend only allows app://j621 through CORS_ALLOWED_ORIGINS, so
gen_env.sh now always writes that origin (plus the split-deploy frontend
when one is given) and --update keeps hand-added origins instead of
overwriting the list.
This commit is contained in:
2026-09-20 19:44:56 -05:00
parent 7f64c6b635
commit 1c6735cde8
3 changed files with 27 additions and 8 deletions
+4 -4
View File
@@ -30,10 +30,10 @@ ALLOWED_HOSTS=j621.rainbow-herring.ts.net,localhost,127.0.0.1
# ---------------------------------------------------------------------------
# Cross-origin access (needed for the separate frontend + backend deploys)
# ---------------------------------------------------------------------------
# The origin the SPA is served from, e.g. https://j621-frontend.<tailnet>.ts.net
# The desktop app (desktop/) is served from app://j621, so add that origin too
# when it should reach this backend:
# CORS_ALLOWED_ORIGINS=https://j621-frontend.<tailnet>.ts.net,app://j621
# The origin the SPA is served from for split deploys, e.g.
# https://j621-frontend.<tailnet>.ts.net. gen_env.sh writes this plus the
# desktop shell's app://j621 origin into the line below (and keeps existing
# entries on --update).
# CORS_ALLOWED_ORIGINS=
# CSRF_TRUSTED_ORIGINS=