Include the desktop origin in generated CORS settings

The backend only allows app://j621 through CORS_ALLOWED_ORIGINS, so
gen_env.sh now always writes that origin (plus the split-deploy frontend
when one is given) and --update keeps hand-added origins instead of
overwriting the list.
This commit is contained in:
2026-09-20 19:44:56 -05:00
parent 7f64c6b635
commit 1c6735cde8
3 changed files with 27 additions and 8 deletions
+4 -4
View File
@@ -30,10 +30,10 @@ ALLOWED_HOSTS=j621.rainbow-herring.ts.net,localhost,127.0.0.1
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
# Cross-origin access (needed for the separate frontend + backend deploys) # Cross-origin access (needed for the separate frontend + backend deploys)
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
# The origin the SPA is served from, e.g. https://j621-frontend.<tailnet>.ts.net # The origin the SPA is served from for split deploys, e.g.
# The desktop app (desktop/) is served from app://j621, so add that origin too # https://j621-frontend.<tailnet>.ts.net. gen_env.sh writes this plus the
# when it should reach this backend: # desktop shell's app://j621 origin into the line below (and keeps existing
# CORS_ALLOWED_ORIGINS=https://j621-frontend.<tailnet>.ts.net,app://j621 # entries on --update).
# CORS_ALLOWED_ORIGINS= # CORS_ALLOWED_ORIGINS=
# CSRF_TRUSTED_ORIGINS= # CSRF_TRUSTED_ORIGINS=
+3 -3
View File
@@ -93,9 +93,9 @@ The SPA asks where the backend is (`/setup`) in production builds:
and give the backend `CORS_ALLOWED_ORIGINS=https://<frontend-host>.<tailnet>.ts.net` and give the backend `CORS_ALLOWED_ORIGINS=https://<frontend-host>.<tailnet>.ts.net`
(plus `CSRF_TRUSTED_ORIGINS` for the admin). (plus `CSRF_TRUSTED_ORIGINS` for the admin).
- **Desktop app** — the Electron shell (`desktop/`) is served from the - **Desktop app** — the Electron shell (`desktop/`) is served from the
`app://j621` origin, so it needs that entry too: `app://j621` origin, which `gen_env.sh` includes in `CORS_ALLOWED_ORIGINS`
`CORS_ALLOWED_ORIGINS=...,app://j621`. The shell's setup screen prints the automatically (add it by hand if you wrote `.env` yourself). The shell's
exact origin when the connection test fails. setup screen prints the exact origin when the connection test fails.
- Without a backend at all, choose **"Continue without a backend"** to run in - Without a backend at all, choose **"Continue without a backend"** to run in
local mode (e621 browsing only). local mode (e621 browsing only).
+20 -1
View File
@@ -86,7 +86,26 @@ FQDN="${FQDN:-$DEFAULT_FQDN}"
# Derive the rest from the tailnet hostname. # Derive the rest from the tailnet hostname.
TS_HOSTNAME="${FQDN%%.*}" TS_HOSTNAME="${FQDN%%.*}"
ALLOWED_HOSTS="$FQDN,localhost,127.0.0.1" ALLOWED_HOSTS="$FQDN,localhost,127.0.0.1"
CORS_ALLOWED_ORIGINS="${FRONTEND:+https://$FRONTEND}"
# Cross-origin access: the optional split-deploy frontend plus the desktop
# shell, which is always a different origin from the backend. On --update the
# existing list is kept, so hand-added origins survive.
CORS_ALLOWED_ORIGINS=""
add_origin() {
[ -n "${1:-}" ] || return 0
case ",$CORS_ALLOWED_ORIGINS," in
*",$1,"*) ;;
*) CORS_ALLOWED_ORIGINS="${CORS_ALLOWED_ORIGINS:+$CORS_ALLOWED_ORIGINS,}$1" ;;
esac
}
if [ "$UPDATE" -eq 1 ]; then
while IFS= read -r origin; do
add_origin "$origin"
done < <(existing CORS_ALLOWED_ORIGINS | tr ',' '\n')
fi
[ -n "$FRONTEND" ] && add_origin "https://$FRONTEND"
add_origin "app://j621"
CSRF_TRUSTED_ORIGINS="${FRONTEND:+https://$FRONTEND}" CSRF_TRUSTED_ORIGINS="${FRONTEND:+https://$FRONTEND}"
J621_SECRET_KEY="$SECRET_KEY" \ J621_SECRET_KEY="$SECRET_KEY" \