diff --git a/.env b/.env new file mode 100644 index 0000000..80809ce --- /dev/null +++ b/.env @@ -0,0 +1,16 @@ +# Committed on purpose - see .gitignore. +# +# Nothing here is a secret. VITE_API_BASE_URL is inlined into the public JS +# bundle at build time, so it is readable by anyone who opens the site; keeping +# it out of git protected nothing and only meant the value had to be remembered +# and re-passed as a --build-arg on every deploy. +# +# Because Vite reads this file during `npm run build`, the Docker build picks it +# up automatically and the --build-arg is no longer required. +# +# Do NOT add anything secret to this file. Every VITE_-prefixed variable ends up +# in the shipped bundle - that is how Vite works, not a misconfiguration. + +# The API's own domain. Must match the backend's API_CORS_ORIGINS pairing: +# this app is served from catalogue.nearle.ai.in and calls the API here. +VITE_API_BASE_URL=https://mcp.nearle.ai.in diff --git a/.gitignore b/.gitignore index 438657a..079b098 100644 --- a/.gitignore +++ b/.gitignore @@ -11,7 +11,17 @@ node_modules dist dist-ssr *.local -.env + +# .env is committed here deliberately. It holds only VITE_API_BASE_URL, which +# Vite inlines into the public bundle anyway - it is visible to anyone who opens +# the site, so ignoring it protected nothing. Committing it means the deploy +# does not depend on remembering a --build-arg. +# +# Anything genuinely secret must NOT go in a VITE_-prefixed variable: it would +# be published in the bundle. Use .env.local (still ignored) for local +# overrides. +!.env +.env.local # Editor directories and files .vscode/*