From 282a494aab11ca74b4e188988ba2b466c02fd9af Mon Sep 17 00:00:00 2001 From: Suriyakumarvijayanayagam Date: Thu, 13 Aug 2026 13:32:25 +0530 Subject: [PATCH] Commit the frontend .env so the API URL is not a remembered build flag VITE_API_BASE_URL is inlined into the public JS bundle at build time, so it is readable by anyone who opens the site. Ignoring it protected nothing and only meant the value had to be remembered and re-passed as --build-arg on every deploy - which is exactly how the bundle ended up pointing at a host that did not exist. Vite reads .env during `npm run build`, so the Docker build now picks the domain up on its own and needs no build arg. Verified: a build with no --build-arg bakes in https://mcp.nearle.ai.in. .env.local stays ignored for local overrides. Nothing secret belongs in a VITE_-prefixed variable - it would be published in the bundle. Co-Authored-By: Claude Opus 5 (1M context) --- .env | 16 ++++++++++++++++ .gitignore | 12 +++++++++++- 2 files changed, 27 insertions(+), 1 deletion(-) create mode 100644 .env diff --git a/.env b/.env new file mode 100644 index 0000000..80809ce --- /dev/null +++ b/.env @@ -0,0 +1,16 @@ +# Committed on purpose - see .gitignore. +# +# Nothing here is a secret. VITE_API_BASE_URL is inlined into the public JS +# bundle at build time, so it is readable by anyone who opens the site; keeping +# it out of git protected nothing and only meant the value had to be remembered +# and re-passed as a --build-arg on every deploy. +# +# Because Vite reads this file during `npm run build`, the Docker build picks it +# up automatically and the --build-arg is no longer required. +# +# Do NOT add anything secret to this file. Every VITE_-prefixed variable ends up +# in the shipped bundle - that is how Vite works, not a misconfiguration. + +# The API's own domain. Must match the backend's API_CORS_ORIGINS pairing: +# this app is served from catalogue.nearle.ai.in and calls the API here. +VITE_API_BASE_URL=https://mcp.nearle.ai.in diff --git a/.gitignore b/.gitignore index 438657a..079b098 100644 --- a/.gitignore +++ b/.gitignore @@ -11,7 +11,17 @@ node_modules dist dist-ssr *.local -.env + +# .env is committed here deliberately. It holds only VITE_API_BASE_URL, which +# Vite inlines into the public bundle anyway - it is visible to anyone who opens +# the site, so ignoring it protected nothing. Committing it means the deploy +# does not depend on remembering a --build-arg. +# +# Anything genuinely secret must NOT go in a VITE_-prefixed variable: it would +# be published in the bundle. Use .env.local (still ignored) for local +# overrides. +!.env +.env.local # Editor directories and files .vscode/*