Include the desktop origin in generated CORS settings
The backend only allows app://j621 through CORS_ALLOWED_ORIGINS, so gen_env.sh now always writes that origin (plus the split-deploy frontend when one is given) and --update keeps hand-added origins instead of overwriting the list.
This commit is contained in:
+20
-1
@@ -86,7 +86,26 @@ FQDN="${FQDN:-$DEFAULT_FQDN}"
|
||||
# Derive the rest from the tailnet hostname.
|
||||
TS_HOSTNAME="${FQDN%%.*}"
|
||||
ALLOWED_HOSTS="$FQDN,localhost,127.0.0.1"
|
||||
CORS_ALLOWED_ORIGINS="${FRONTEND:+https://$FRONTEND}"
|
||||
|
||||
# Cross-origin access: the optional split-deploy frontend plus the desktop
|
||||
# shell, which is always a different origin from the backend. On --update the
|
||||
# existing list is kept, so hand-added origins survive.
|
||||
CORS_ALLOWED_ORIGINS=""
|
||||
add_origin() {
|
||||
[ -n "${1:-}" ] || return 0
|
||||
case ",$CORS_ALLOWED_ORIGINS," in
|
||||
*",$1,"*) ;;
|
||||
*) CORS_ALLOWED_ORIGINS="${CORS_ALLOWED_ORIGINS:+$CORS_ALLOWED_ORIGINS,}$1" ;;
|
||||
esac
|
||||
}
|
||||
if [ "$UPDATE" -eq 1 ]; then
|
||||
while IFS= read -r origin; do
|
||||
add_origin "$origin"
|
||||
done < <(existing CORS_ALLOWED_ORIGINS | tr ',' '\n')
|
||||
fi
|
||||
[ -n "$FRONTEND" ] && add_origin "https://$FRONTEND"
|
||||
add_origin "app://j621"
|
||||
|
||||
CSRF_TRUSTED_ORIGINS="${FRONTEND:+https://$FRONTEND}"
|
||||
|
||||
J621_SECRET_KEY="$SECRET_KEY" \
|
||||
|
||||
Reference in New Issue
Block a user