Compare commits

..
3 Commits
Author SHA1 Message Date
rmancinas 3b02c6944f chore(release): v1.0.17
Build and Push Images / Build jorgecuadros-api (push) Successful in 3m16s
Build and Push Images / Build jorgecuadros-web (push) Successful in 2m31s
Deploy on tag / Deploy to galactus (push) Successful in 5m33s
2026-08-11 12:56:52 -07:00
rmancinasandClaude Opus 5 683fd37b08 docs(deploy): stop documenting API_ORIGIN as required
The swarm stack still hard-failed on an unset API_ORIGIN, and both the env
template and the README told the reader to pin it — the exact habit the derived
origin was meant to end. Make it an optional override everywhere, and say that
WEB_ORIGIN is now a list.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 12:56:50 -07:00
rmancinasandClaude Opus 5 14c6183aa2 feat(deploy): derive the API origin from the page, not from a pinned env var
Build and Push Images / Build jorgecuadros-web (push) Successful in 1m55s
Build and Push Images / Build jorgecuadros-api (push) Successful in 2m35s
The browser hard-required API_ORIGIN, so every move of the server — tailnet
today, the 192.168.1.0 office LAN later, a temporary demo domain in between —
meant editing the deploy env and redeploying. Worse, an http:// API origin on a
page served over TLS is blocked outright as mixed active content, which is what
broke the demo on https://jorgecuadros.freakma.com.

The browser now derives the origin from window.location the way a PHP app
would: same host on port 3001 over plain HTTP, or the same-origin /api path
under https (the reverse proxy strips the prefix). API_ORIGIN survives as an
optional override for a deployment that genuinely splits the two hosts, and SSR
still reads process.env because a derived origin is browser-only.

WEB_ORIGIN becomes a comma-separated list to match: one deployment is now
reached under several origins, and a credentialed fetch from an unlisted one
gets no CORS headers and fails.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 12:55:32 -07:00
11 changed files with 77 additions and 29 deletions
+8 -1
View File
@@ -96,7 +96,14 @@ NEXT_PUBLIC_API_ORIGIN=http://localhost:3001
```
The API loads `DATABASE_URL`, `SESSION_SECRET`, `WEB_ORIGIN`, and optional
`PORT` (default `3001`). The web app only needs `NEXT_PUBLIC_API_ORIGIN`.
`PORT` (default `3001`). `WEB_ORIGIN` is comma-separated — list every origin the
app is reached under, or credentialed fetches from the missing ones fail CORS.
The web app needs no API URL of its own: the browser derives it from the page it
loaded (same host on port `3001` over plain HTTP, or the same-origin `/api` path
behind a TLS proxy). Set `NEXT_PUBLIC_API_ORIGIN` (dev) or `API_ORIGIN` (deploy,
read at request time) only to override that — for instance when running the API
on a non-default port.
### 3. Start MySQL
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@jorgecuadros/api",
"version": "1.0.16",
"version": "1.0.17",
"private": true,
"scripts": {
"build": "nest build",
+13 -1
View File
@@ -60,7 +60,19 @@ async function bootstrap() {
app.use(passport.initialize());
app.use(passport.session());
app.enableCors({ credentials: true, origin: process.env.WEB_ORIGIN ?? "http://localhost:3000" });
// The same deployment is reached under several origins — the office LAN IP,
// the tailnet name, the demo domain — and the browser derives the API origin
// from whichever one served the page (apps/web/src/lib/api.ts). So WEB_ORIGIN
// is a comma-separated LIST, not a single value. A request whose Origin is
// not listed gets no CORS headers and the credentialed fetch fails, so add an
// entry when a new way of reaching the app is introduced. Same-origin setups
// (web and API behind one proxy) never hit CORS at all.
const webOrigins = (process.env.WEB_ORIGIN ?? "http://localhost:3000")
.split(",")
.map((o) => o.trim())
.filter(Boolean);
app.enableCors({ credentials: true, origin: webOrigins });
const port = process.env.PORT ? Number(process.env.PORT) : 3001;
await app.listen(port);
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@jorgecuadros/web",
"version": "1.0.16",
"version": "1.0.17",
"private": true,
"scripts": {
"dev": "next dev -p 4500",
+9 -10
View File
@@ -8,19 +8,18 @@ export const metadata = {
"Plataforma interna unificada de clientes, servicios y seguros.",
};
// The browser talks to the API cross-origin, so it needs the API URL at
// runtime. NEXT_PUBLIC_* would bake it at build time (one URL per image); we
// want the URL to come from the deploy .env instead. So read it here on the
// server per request and inject it as window.__API_ORIGIN__ (see lib/api.ts).
// force-dynamic guarantees process.env is read at request time, never baked
// into a static prerender.
// API_ORIGIN is an OPTIONAL override, read here on the server per request and
// injected as window.__API_ORIGIN__ (see lib/api.ts). NEXT_PUBLIC_* would bake
// it at build time (one URL per image); reading it here keeps one image usable
// anywhere. Left unset — the normal case — this injects the empty string and
// lib/api.ts derives the origin from window.location instead, so the app
// follows the server when it moves without an env edit. force-dynamic
// guarantees process.env is read at request time, never baked into a static
// prerender.
export const dynamic = "force-dynamic";
export default function RootLayout({ children }: { children: ReactNode }) {
const apiOrigin =
process.env.API_ORIGIN ??
process.env.NEXT_PUBLIC_API_ORIGIN ??
"http://localhost:3001";
const apiOrigin = process.env.API_ORIGIN ?? "";
// Same reason as the API origin: read on the server per request so the built
// image is not pinned to one build identity in its client bundle.
const build = readBuildInfoFromEnv();
+16 -5
View File
@@ -82,15 +82,26 @@ import type {
UserRow,
} from "./types";
// Resolve the API origin at runtime, not build time. In the browser it comes
// from window.__API_ORIGIN__, injected server-side by the root layout from the
// deploy .env (API_ORIGIN) — so one built image serves any deployment. On the
// server (SSR) read process.env directly. NEXT_PUBLIC_API_ORIGIN stays as the
// dev/build fallback.
// Resolve the API origin at runtime, not build time — so one built image serves
// any deployment and the app follows the box when it moves (tailnet today,
// 192.168.1.x office LAN later) with no config change.
//
// In the browser, derive the origin from the page's own location, the way a PHP
// app would. An explicit API_ORIGIN (injected as window.__API_ORIGIN__ by the
// root layout) still wins when a deployment genuinely splits the two hosts.
// On the server (SSR) read process.env directly — a derived origin is
// browser-only, and "/api" is not fetchable server-side.
function resolveApiOrigin(): string {
if (typeof window !== "undefined") {
const injected = (window as { __API_ORIGIN__?: string }).__API_ORIGIN__;
if (injected) return injected;
const { protocol, hostname } = window.location;
// Over TLS the API must share the page's origin or the browser blocks the
// call as mixed active content. The reverse proxy maps /api to the API.
if (protocol === "https:") return "/api";
// Plain HTTP: same host, API port. 3001 is the port the API container
// publishes everywhere (deploy/galactus/jorgecuadros-app.compose.yml).
return `http://${hostname}:3001`;
}
return (
process.env.API_ORIGIN ??
+6 -2
View File
@@ -132,8 +132,12 @@ services:
dns_search:
- ${TAILNET_SUFFIX:-tail01aa2.ts.net}
environment:
# Public API URL the browser calls (injected at runtime, see layout.tsx).
API_ORIGIN: ${API_ORIGIN:?API_ORIGIN must be set}
# OPTIONAL override of the API URL the browser calls (injected at runtime,
# see layout.tsx). Leave it unset: the browser then derives the origin
# from the page it loaded — same host on port 3001 over plain HTTP, or
# /api behind a TLS-terminating proxy. Set it only when the API really
# lives on a different host than the web app.
API_ORIGIN: ${API_ORIGIN:-}
ports:
- "${WEB_PORT:-3000}:3000"
depends_on:
+15 -4
View File
@@ -8,10 +8,21 @@
APP_TAG=latest
# --- Public URLs (what the end user's BROWSER hits) ---------------------------
# API_ORIGIN is injected into the web app at runtime and used for browser fetches
# + document download links, so it must be browser-reachable (not swarm-internal).
# WEB_ORIGIN is the web app's own public origin; the API allows it via CORS.
API_ORIGIN=http://192.168.4.212:3001
# API_ORIGIN is OPTIONAL and normally left unset. The browser derives the API
# origin from the page it loaded (apps/web/src/lib/api.ts): same host on port
# 3001 over plain HTTP, or the same-origin /api path when the page is served
# over https by a TLS-terminating proxy that maps /api to the API. That is what
# lets the same deployment move — tailnet, office LAN, demo domain — untouched.
# Set it only when the API genuinely lives on a different host than the web app;
# it is used for browser fetches AND document download links, so it must be
# browser-reachable (never a swarm-internal name).
#API_ORIGIN=http://192.168.4.212:3001
#
# WEB_ORIGIN is the list of public origins the web app is reached under; the API
# allows them via CORS. COMMA-SEPARATED — one deployment is reachable under
# several origins (LAN IP, tailnet name, demo domain) and a credentialed fetch
# from an origin missing here gets no CORS headers and fails. A same-origin
# setup (web + API behind one proxy) never hits CORS at all.
WEB_ORIGIN=http://192.168.4.212:3000
# Published ports on the swarm host.
+6 -2
View File
@@ -92,8 +92,12 @@ services:
labels:
io.jorgecuadros.role: "web"
environment:
# Public API URL the browser calls (injected at runtime, see layout.tsx).
API_ORIGIN: ${API_ORIGIN:?API_ORIGIN must be set}
# OPTIONAL override of the API URL the browser calls (injected at runtime,
# see layout.tsx). Leave it unset: the browser then derives the origin
# from the page it loaded — same host on port 3001 over plain HTTP, or
# /api behind a TLS-terminating proxy. Set it only when the API really
# lives on a different host than the web app.
API_ORIGIN: ${API_ORIGIN:-}
ports:
- target: 3000
published: ${WEB_PORT:-3000}
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "jorgecuadros-platform",
"version": "1.0.16",
"version": "1.0.17",
"private": true,
"workspaces": [
"apps/*",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@jorgecuadros/database",
"version": "1.0.16",
"version": "1.0.17",
"private": true,
"main": "generated/client/index.js",
"types": "generated/client/index.d.ts",