Seven call sites used fetch() directly instead of the api client in src/api/client.js, so they sent no Authorization header. Four of them hit endpoints the backend guards with a permission, and every one of those returned 401 for any signed-in user: AdminPage /api/admin/training/upload-dataset (upload_train_test) AdminPage /api/admin/training/allocate-discounts (allocate_discounts) UserPage /api/user/products/add (add_product) UserPage /api/user/products/upload-file (upload_batch_products) The remaining three hit public GETs and worked, but bypassed VITE_API_BASE_URL and the central 401 handler just the same. Route all seven through the client and add the endpoints it was missing. Multipart uploads still need a raw fetch, because the browser has to set its own Content-Type to carry the boundary, so that is now one upload() helper that attaches the auth header and routes 401s to the logout handler rather than three copies that did neither. handleAllocateDiscounts only acted on res.ok, so a 401 or 403 left the panel looking idle with no indication that nothing had been allocated. It surfaces the error now. Take VITE_API_BASE_URL as a Docker build arg. The app is served from catalogue.nearle.ai.in and the API from mcp.catalogue.nearle.ai.in, and Vite inlines env vars at build time, so setting this on the running container does nothing - it has to reach npm run build. Defaults to empty, which keeps requests relative for the same-origin nginx proxy. Also revoke the object URL after the sample-CSV download. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
25 lines
1.1 KiB
Plaintext
25 lines
1.1 KiB
Plaintext
# Base URL of the FastAPI backend.
|
|
#
|
|
# Leave it unset for local development: Vite's dev proxy (see vite.config.js)
|
|
# forwards /api/* to http://127.0.0.1:8000, so relative requests just work and
|
|
# no CORS setup is needed.
|
|
#
|
|
# Set it whenever the API is served from a different origin than the app. In
|
|
# production the React app is served from catalogue.nearle.ai.in and the API
|
|
# lives on its own subdomain, so the deployed build needs:
|
|
#
|
|
# VITE_API_BASE_URL=https://mcp.catalogue.nearle.ai.in
|
|
#
|
|
# No trailing slash - src/api/client.js concatenates paths that already start
|
|
# with "/api".
|
|
#
|
|
# IMPORTANT: Vite inlines this at BUILD time, not at run time. Setting it on
|
|
# the running container does nothing; it has to be passed to `npm run build`.
|
|
# The Dockerfile exposes it as a build arg for exactly this reason:
|
|
#
|
|
# docker build --build-arg VITE_API_BASE_URL=https://mcp.catalogue.nearle.ai.in .
|
|
#
|
|
# Whatever origin you set here must also appear in the backend's
|
|
# API_CORS_ORIGINS, or the browser will block every response.
|
|
# VITE_API_BASE_URL=https://mcp.catalogue.nearle.ai.in
|