agnets done
This commit is contained in:
54
.env
54
.env
@@ -1,41 +1,19 @@
|
||||
# ============================================================================
|
||||
# Krow frontend — example environment
|
||||
# Local development against the deployed backend.
|
||||
#
|
||||
# Copy to .env and adjust. .env is gitignored.
|
||||
#
|
||||
# cp .env.example .env
|
||||
#
|
||||
# Vite only exposes variables prefixed with VITE_ to client code, and it reads
|
||||
# these at build/dev-server start — changing one needs a restart, not a reload.
|
||||
# ============================================================================
|
||||
|
||||
# Where the browser sends API requests.
|
||||
#
|
||||
# A SAME-ORIGIN PATH, not a host. The browser asks its own origin for
|
||||
# /api/v1/..., and something on that origin forwards it to the Go API:
|
||||
# in development the Vite proxy (see `server.proxy` in vite.config.js), in
|
||||
# production the same web server that serves the built assets (see nginx.conf).
|
||||
#
|
||||
# browser → localhost:5173/api/v1 → Vite proxy → 127.0.0.1:8080/api/v1
|
||||
#
|
||||
# THIS MUST STAY A PATH. Pointing it at http://127.0.0.1:8080/api/v1 makes every
|
||||
# request cross-site, and the session cookie stops working in two separate ways:
|
||||
#
|
||||
# 1. The cookie is SameSite=Lax, and a Lax cookie is not sent on a cross-site
|
||||
# subresource request. A browser treats localhost:5173 and 127.0.0.1:8080
|
||||
# as different sites, so the cookie would be set at login and then never
|
||||
# sent again.
|
||||
# 2. Because the transport sends `credentials: 'include'`, the browser
|
||||
# requires `Access-Control-Allow-Credentials: true` on the preflight
|
||||
# response. The API does not send it — deliberately, because the supported
|
||||
# arrangement is same-origin — so Chrome discards the preflight and never
|
||||
# dispatches the real request. The symptom is an OPTIONS that answers 204
|
||||
# followed by a POST that never reaches the server at all.
|
||||
#
|
||||
# Both failures are silent from the page's point of view, which is why this
|
||||
# comment is longer than the value.
|
||||
# The dev server proxies /api and /health to VITE_API_PROXY_TARGET, so the app
|
||||
# talks to the deployment through its own origin — which is what keeps the
|
||||
# session cookie (Secure, SameSite=Lax, host-scoped) working in the browser.
|
||||
VITE_API_BASE_URL=/api/v1
|
||||
|
||||
# Where the Vite dev proxy forwards /api. Only read by vite.config.js, never by
|
||||
# client code.
|
||||
VITE_API_PROXY_TARGET=https://mcp.krowforce.com
|
||||
|
||||
# Owliver's agent endpoint.
|
||||
#
|
||||
# Relative FOR DEVELOPMENT ONLY: vite proxies it to VITE_API_PROXY_TARGET above.
|
||||
# The production image cannot use a relative value — nginx serves it as a static
|
||||
# path and answers a run POST with 405 — so Dockerfile passes an absolute URL as
|
||||
# a build arg instead. Changing this file does not change what ships.
|
||||
#
|
||||
# Empty is what it was, and an empty value is not a broken panel: the provider
|
||||
# answers every question with "Owliver is not configured on this deployment",
|
||||
# deliberately, because a panel that quietly does nothing is harder to diagnose.
|
||||
VITE_AGENT_API=/api/v1
|
||||
|
||||
Reference in New Issue
Block a user