fix(auth): add Vite dev proxy to fix SameSite=Strict cookie on page reload
Chrome 89+ treats http://localhost and https://localhost as different sites (schemeful same-site). The refreshToken cookie (SameSite=Strict) was not sent when the Vite dev server (HTTP) made cross-origin fetch calls to the .NET backend (HTTPS), causing a 401 on every page reload. Fix: route /api/* through the Vite dev server proxy so all requests stay same-origin. The cookie is now always sent and auth sessions survive reloads. - vite.config.ts: proxy /api → https://localhost:7221 (secure:false for dev cert) - .env.example: document proxy vs direct mode, set default VITE_API_BASE_URL to empty - config.ts: accept empty string as valid apiBaseUrl alongside full URLs Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
This commit is contained in:
@@ -6,7 +6,8 @@ import { z } from 'zod';
|
||||
* once and only warns in development — production trusts the build-time env.
|
||||
*/
|
||||
const configSchema = z.object({
|
||||
apiBaseUrl: z.string().url(),
|
||||
// Empty string = use Vite proxy (same-origin); a full URL = direct mode.
|
||||
apiBaseUrl: z.union([z.literal(''), z.string().url()]),
|
||||
});
|
||||
|
||||
export type AppConfig = z.infer<typeof configSchema>;
|
||||
|
||||
Reference in New Issue
Block a user