diff --git a/src/api/nutrition.ts b/src/api/nutrition.ts index 08edc32..2af46c0 100644 --- a/src/api/nutrition.ts +++ b/src/api/nutrition.ts @@ -26,7 +26,29 @@ * correct; the data has to catch up. */ -const NUTRITION_BASE = 'https://mcp.nearle.ai.in/api'; +/* + * Through this console's OWN origin, not the service's. + * + * `/ingest` is proxied to mcp.nearle.ai.in by nginx in production and by vite in + * development, so this is same-origin either way and CORS does not enter into + * it. + * + * It used to be the absolute `https://mcp.nearle.ai.in/api`, and that works only + * where the service's allowlist names the calling origin. Measured 30 Sep 2026: + * a request carrying `Origin: https://app.nearledaily.com` comes back with + * `Access-Control-Allow-Origin` and one carrying + * `Origin: https://platform.nearledaily.com` comes back without it. So the + * browser dropped every response here, `forProduct` returned null, and the panel + * showed "No health score available for this product yet" for every product — + * the same product that renders fine in the merchant console. + * + * `vite.config.ts` called this exactly: "it works on every developer machine and + * fails the moment it is deployed, which is the worst order to find out." + * + * The proxy also attaches the ingest API key, which this endpoint does not need + * and does not mind. + */ +const NUTRITION_BASE = '/ingest/api'; /** How confident the service is that it matched the right source record. */ export const LOW_CONFIDENCE = 0.7;