# ============================================================================
# Krow frontend — example environment
#
# Copy to .env and adjust. .env is gitignored.
#
#   cp .env.example .env
#
# Vite only exposes variables prefixed with VITE_ to client code, and it reads
# these at build/dev-server start — changing one needs a restart, not a reload.
# ============================================================================

# Where the browser sends API requests.
#
# A SAME-ORIGIN PATH, not a host. The browser asks its own origin for
# /api/v1/..., and something on that origin forwards it to the Go API:
# in development the Vite proxy (see `server.proxy` in vite.config.js), in
# production the same web server that serves the built assets (see nginx.conf).
#
#     browser → localhost:5173/api/v1 → Vite proxy → 127.0.0.1:8080/api/v1
#
# THIS MUST STAY A PATH. Pointing it at http://127.0.0.1:8080/api/v1 makes every
# request cross-site, and the session cookie stops working in two separate ways:
#
#   1. The cookie is SameSite=Lax, and a Lax cookie is not sent on a cross-site
#      subresource request. A browser treats localhost:5173 and 127.0.0.1:8080
#      as different sites, so the cookie would be set at login and then never
#      sent again.
#   2. Because the transport sends `credentials: 'include'`, the browser
#      requires `Access-Control-Allow-Credentials: true` on the preflight
#      response. The API does not send it — deliberately, because the supported
#      arrangement is same-origin — so Chrome discards the preflight and never
#      dispatches the real request. The symptom is an OPTIONS that answers 204
#      followed by a POST that never reaches the server at all.
#
# Both failures are silent from the page's point of view, which is why this
# comment is longer than the value.
VITE_API_BASE_URL=/api/v1

# Where the Vite dev proxy forwards /api. Only read by vite.config.js, never by
# client code.
VITE_API_PROXY_TARGET=https://mcp.krowforce.com
