diff --git a/Dockerfile b/Dockerfile index 0296ae7..c697806 100644 --- a/Dockerfile +++ b/Dockerfile @@ -19,6 +19,20 @@ COPY package*.json ./ RUN npm ci --no-audit --no-fund COPY . . + +# Where the bundle points at the backend, fixed HERE rather than left to `.env`. +# +# Deployment platforms write their own `.env` into the source directory before +# building — Dokploy does — which overwrites the committed one and takes +# VITE_API_BASE with it. The build then fell through to a same-origin path and +# the console called `https:///fiesta/live/api/...`. A build +# argument outranks the file, so the host survives that overwrite. +# +# Override per environment with `--build-arg VITE_API_BASE=...` (Dokploy: Build +# Args), e.g. to point a staging console at a staging Fiesta. +ARG VITE_API_BASE="https://fiesta.nearle.app" +ENV VITE_API_BASE=$VITE_API_BASE + RUN npm run build # Stage 2 — serve diff --git a/src/api/client.ts b/src/api/client.ts index 6a46c6b..f7d48cc 100644 --- a/src/api/client.ts +++ b/src/api/client.ts @@ -20,14 +20,31 @@ import type { FiestaEnvelope } from './types'; * this, production means that" is invisible from the outside, and someone * reading `.env` to find the backend would have found nothing. * - * The `'/fiesta'` fallback is for a build with no `.env` at all. It routes - * through the dev proxy (`vite.config.ts`) or nginx (`nginx.conf.template`), - * both of which forward to the same host — so a missing variable degrades to a - * working same-origin path rather than to a broken one. + * The fallback is the REAL HOST, not the same-origin `/fiesta` prefix it used + * to be. That prefix looked like a safe degradation and was not: a platform + * that writes its own `.env` into the build context (Dokploy does) erases the + * committed `VITE_API_BASE`, and the bundle then aims every call at whatever + * domain serves the console — `https://app.nearledaily.com/fiesta/live/api/...` + * instead of Fiesta. It kept working only because nginx happens to proxy that + * prefix, which is what made the misconfiguration invisible. * - * Override per machine with `.env.local`, which is gitignored. + * Defaulting to the host means a missing variable can no longer silently + * re-point the backend at the console's own domain. `Dockerfile` also passes + * `VITE_API_BASE` as a build argument, so the value survives an overwritten + * `.env`. + * + * A trailing slash is stripped: every path below starts with `/`, and + * `https://host//live/api/...` is a different URL to the upstream router. + * + * Override per machine with `.env.local`, which is gitignored — set it to + * `/fiesta` to route through the dev proxy or nginx instead. */ -export const API_BASE = import.meta.env['VITE_API_BASE'] ?? '/fiesta'; +const configuredBase = (import.meta.env['VITE_API_BASE'] ?? '').trim(); + +export const API_BASE = (configuredBase || 'https://fiesta.nearle.app').replace( + /\/+$/, + '', +); /** Every console route lives under this prefix. */ export const WEB = '/live/api/v1/web';