Commit the frontend .env so the API URL is not a remembered build flag

VITE_API_BASE_URL is inlined into the public JS bundle at build time, so it is
readable by anyone who opens the site. Ignoring it protected nothing and only
meant the value had to be remembered and re-passed as --build-arg on every
deploy - which is exactly how the bundle ended up pointing at a host that did
not exist.

Vite reads .env during `npm run build`, so the Docker build now picks the domain
up on its own and needs no build arg. Verified: a build with no --build-arg
bakes in https://mcp.nearle.ai.in.

.env.local stays ignored for local overrides. Nothing secret belongs in a
VITE_-prefixed variable - it would be published in the bundle.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Suriyakumarvijayanayagam
2026-08-13 13:32:25 +05:30
parent 0dd8427817
commit 282a494aab
2 changed files with 27 additions and 1 deletions

12
.gitignore vendored
View File

@@ -11,7 +11,17 @@ node_modules
dist
dist-ssr
*.local
.env
# .env is committed here deliberately. It holds only VITE_API_BASE_URL, which
# Vite inlines into the public bundle anyway - it is visible to anyone who opens
# the site, so ignoring it protected nothing. Committing it means the deploy
# does not depend on remembering a --build-arg.
#
# Anything genuinely secret must NOT go in a VITE_-prefixed variable: it would
# be published in the bundle. Use .env.local (still ignored) for local
# overrides.
!.env
.env.local
# Editor directories and files
.vscode/*