diff --git a/apps/pwa/vite.config.ts b/apps/pwa/vite.config.ts index 3182c98..ede94d0 100644 --- a/apps/pwa/vite.config.ts +++ b/apps/pwa/vite.config.ts @@ -44,10 +44,13 @@ export default defineConfig({ }), ], server: { - // Allow the internal split-DNS domain (and any subdomain) to reach the dev - // server through the reverse proxy / tunnel. A leading dot matches the apex - // and all subdomains. Dev-server only — production builds ignore this. - allowedHosts: ['.bergerhouse.net'], + // Dev box reached through the Pangolin/newt tunnel: Vite's default host check + // 403s any non-localhost Host header ("Blocked request"), which the tunnel + // health check reads as unhealthy. `true` accepts any host (fine for a private + // throwaway dev tunnel); replace with e.g. ['familysync.example.com'] to scope it. + allowedHosts: true, + // Listen on all interfaces so newt can reach Vite via the box IP, not just localhost. + host: true, proxy: { '/health': 'http://localhost:3000', '/api': 'http://localhost:3000', diff --git a/docker-compose.dev.yml b/docker-compose.dev.yml index 9b07269..08201be 100644 --- a/docker-compose.dev.yml +++ b/docker-compose.dev.yml @@ -9,6 +9,10 @@ services: - ./apps/api/src:/app/apps/api/src environment: NODE_ENV: development + # Local-dev only: skip OIDC and authenticate as Dev User id 1. Guarded by + # NODE_ENV !== 'production' (and the production image bakes NODE_ENV=production), + # so this can never activate in a shipped image. Required by the e2e harness. + DEV_AUTH_BYPASS: 'true' mariadb: ports: