Chrome 89+ treats http://localhost and https://localhost as different sites (schemeful same-site). The refreshToken cookie (SameSite=Strict) was not sent when the Vite dev server (HTTP) made cross-origin fetch calls to the .NET backend (HTTPS), causing a 401 on every page reload. Fix: route /api/* through the Vite dev server proxy so all requests stay same-origin. The cookie is now always sent and auth sessions survive reloads. - vite.config.ts: proxy /api → https://localhost:7221 (secure:false for dev cert) - .env.example: document proxy vs direct mode, set default VITE_API_BASE_URL to empty - config.ts: accept empty string as valid apiBaseUrl alongside full URLs Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
12 lines
539 B
Bash
12 lines
539 B
Bash
# Base URL of the SlpModularCms .NET API.
|
|
#
|
|
# LOCAL DEV (recommended): leave empty and configure the Vite proxy in
|
|
# vite.config.ts. The proxy forwards /api/* to the backend so all requests
|
|
# stay same-origin — required for the SameSite=Strict refresh-token cookie.
|
|
VITE_API_BASE_URL=
|
|
|
|
# DIRECT (no proxy): point to the backend URL. CORS must allow this origin
|
|
# with credentials, and SameSite may block the cookie on page reload if the
|
|
# schemes differ (e.g. http frontend → https backend).
|
|
# VITE_API_BASE_URL=https://localhost:7221
|