Include the desktop origin in generated CORS settings

The backend only allows app://j621 through CORS_ALLOWED_ORIGINS, so
gen_env.sh now always writes that origin (plus the split-deploy frontend
when one is given) and --update keeps hand-added origins instead of
overwriting the list.
This commit is contained in:
2026-09-20 19:44:56 -05:00
parent 7f64c6b635
commit 1c6735cde8
3 changed files with 27 additions and 8 deletions
+3 -3
View File
@@ -93,9 +93,9 @@ The SPA asks where the backend is (`/setup`) in production builds:
and give the backend `CORS_ALLOWED_ORIGINS=https://<frontend-host>.<tailnet>.ts.net`
(plus `CSRF_TRUSTED_ORIGINS` for the admin).
- **Desktop app** — the Electron shell (`desktop/`) is served from the
`app://j621` origin, so it needs that entry too:
`CORS_ALLOWED_ORIGINS=...,app://j621`. The shell's setup screen prints the
exact origin when the connection test fails.
`app://j621` origin, which `gen_env.sh` includes in `CORS_ALLOWED_ORIGINS`
automatically (add it by hand if you wrote `.env` yourself). The shell's
setup screen prints the exact origin when the connection test fails.
- Without a backend at all, choose **"Continue without a backend"** to run in
local mode (e621 browsing only).