# ============================================================================ # Krow frontend — example environment # # Copy to .env and adjust. .env is gitignored. # # cp .env.example .env # # Vite only exposes variables prefixed with VITE_ to client code, and it reads # these at build/dev-server start — changing one needs a restart, not a reload. # ============================================================================ # Where the browser sends API requests. # # A SAME-ORIGIN PATH, not a host. The browser asks its own origin for # /api/v1/..., and something on that origin forwards it to the Go API: # in development the Vite proxy (see `server.proxy` in vite.config.js), in # production the same web server that serves the built assets (see nginx.conf). # # browser → localhost:5173/api/v1 → Vite proxy → 127.0.0.1:8080/api/v1 # # THIS MUST STAY A PATH. Pointing it at http://127.0.0.1:8080/api/v1 makes every # request cross-site, and the session cookie stops working in two separate ways: # # 1. The cookie is SameSite=Lax, and a Lax cookie is not sent on a cross-site # subresource request. A browser treats localhost:5173 and 127.0.0.1:8080 # as different sites, so the cookie would be set at login and then never # sent again. # 2. Because the transport sends `credentials: 'include'`, the browser # requires `Access-Control-Allow-Credentials: true` on the preflight # response. The API does not send it — deliberately, because the supported # arrangement is same-origin — so Chrome discards the preflight and never # dispatches the real request. The symptom is an OPTIONS that answers 204 # followed by a POST that never reaches the server at all. # # Both failures are silent from the page's point of view, which is why this # comment is longer than the value. VITE_API_BASE_URL=/api/v1 # PRODUCTION BUILDS ARE DIFFERENT. The relative value above is correct only # where something on the page's own origin forwards /api — the Vite proxy in # development. The deployed frontend at platform.krowforce.com is a static nginx # host with no such forward (see nginx.conf: no `location /api/`), so a relative # path makes the login POST land on a static route and answer 405 Method Not # Allowed. # # The production value is therefore absolute, and it is set as a build-time # environment variable rather than here, because .dockerignore excludes .env* # and no env file reaches the image build: # # ARG VITE_API_BASE_URL=https://mcp.krowforce.com/api/v1 (see Dockerfile) # # platform.krowforce.com and mcp.krowforce.com are different origins but the # same site, so the SameSite=Lax session cookie is still sent — which is why # production works cross-origin while localhost cannot. # Where the Vite dev proxy forwards /api. Only read by vite.config.js, never by # client code. VITE_API_PROXY_TARGET=https://mcp.krowforce.com