Ask where the backend lives on first start (runtime setup)
Replaces the build-time VITE_API_BASE knob with a runtime setup screen so one build works same-origin and cross-origin: - frontend/src/lib/backend.ts stores the API origin in localStorage (empty = same origin). DEFAULT_BACKEND_URL is the clearly marked, easily edited prefilled default — the matrix.org equivalent; set it to your public API origin. - Production builds show /setup before anything else on first start, with a connection test against /health (or leave it blank for this server). The route stays reachable from Account -> Backend connection; switching backends clears the previous backend's token and reloads. - Input normalisation: scheme defaulted (https, http for localhost), trailing slashes trimmed; a failed cross-origin test points at CORS_ALLOWED_ORIGINS. - Dev keeps defaulting to the same-origin Vite proxy; /setup can be visited manually. Verified: normalisation cases in Node, /health returns CORS headers for an allowed origin, tsc/oxlint/build clean.
This commit is contained in:
@@ -31,12 +31,13 @@ Project constraints (do not regress):
|
||||
MariaDB/Redis come from docker-compose.yml.
|
||||
- Deployment will be Docker-based (compose); do not add systemd/cron unit
|
||||
files for scheduling — use the container setup for timers/workers.
|
||||
- Same-origin and cross-origin frontends both work: the SPA uses relative
|
||||
URLs unless built with VITE_API_BASE, the backend allows extra origins
|
||||
via CORS_ALLOWED_ORIGINS (plus CSRF_TRUSTED_ORIGINS for the admin), and
|
||||
API media URLs are absolute (built from the request host), so signed
|
||||
files load cross-origin too. TRUST_PROXY_HEADERS=true is required behind
|
||||
a TLS-terminating proxy.
|
||||
- Same-origin and cross-origin frontends both work: a production build asks
|
||||
for the backend origin on first start (/setup, stored in localStorage;
|
||||
DEFAULT_BACKEND_URL in frontend/src/lib/backend.ts is the prefilled
|
||||
default), the backend allows extra origins via CORS_ALLOWED_ORIGINS (plus
|
||||
CSRF_TRUSTED_ORIGINS for the admin), and API media URLs are absolute
|
||||
(built from the request host), so signed files load cross-origin too.
|
||||
TRUST_PROXY_HEADERS=true is required behind a TLS-terminating proxy.
|
||||
- No server-side media processing: the home server cannot handle it.
|
||||
Compression/optimization runs client-side (WebCodecs + WASM in a worker)
|
||||
and the server only applies the result via POST /api/files/J-x/optimize/.
|
||||
|
||||
Reference in New Issue
Block a user