From 94f43a326ee1261304e250e8307f63c38371b7d8 Mon Sep 17 00:00:00 2001 From: Suriyakumarvijayanayagam Date: Fri, 14 Aug 2026 15:42:34 +0530 Subject: [PATCH] Point CORS at the frontend's real domain - it is spelled "catalouge" The frontend loaded but could not call the API at all: every preflight from the browser came back with no Access-Control-Allow-Origin header, so each request was blocked client-side while the server logged nothing wrong. API_CORS_ORIGINS was set to catalogue.nearle.ai.in. The host Traefik actually serves is catalouge.nearle.ai.in - the o and u transposed. The correctly spelled domain does not resolve at all, which is why checking the "frontend" only ever returned a connection error and looked like a network problem. Both spellings are now listed, so this keeps working if the typo is corrected in Dokploy later. Verified against the live API: a preflight from https://catalouge.nearle.ai.in previously returned 400 with no allow-origin. Co-Authored-By: Claude Opus 5 (1M context) --- .env.production | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/.env.production b/.env.production index 1362baa..0010331 100644 --- a/.env.production +++ b/.env.production @@ -19,8 +19,15 @@ PORTS=3000,8000 # --- CORS ------------------------------------------------------------------ # The FRONTEND's origin, not this API's. Wrong value = the browser blocks every -# response while the server logs healthy 200s. -API_CORS_ORIGINS=https://catalogue.nearle.ai.in +# response while the server logs healthy 200s - which is exactly what happened +# here: this was set to catalogue.nearle.ai.in, but the domain Traefik actually +# serves is spelled "catalouge". That host does not even resolve, so nothing +# pointed at the mistake except a silently failing UI. +# +# Both spellings are listed so this keeps working if the typo is ever corrected +# in Dokploy. Exact origins, never a wildcard: the app sends an Authorization +# header, and browsers reject credentialed requests to a wildcard origin. +API_CORS_ORIGINS=https://catalouge.nearle.ai.in,https://catalogue.nearle.ai.in # --- Authentication -------------------------------------------------------- AUTH_ENABLED=true