## Description Adds optional env **`ADDITIONAL_TRUSTED_ORIGINS`**: comma-separated browser origins that are trusted for **CORS (`/api/*`)**, **Stripe return URLs**, **Better Auth `trustedOrigins`**, and **dynamic web OIDC redirect URIs**. LAN / non-localhost Capacitor dev (e.g. Pocket + Vite on `https://10.x:5273`) no longer relies on broad private-IP regex; operators list exact origins in `.env.local` and restart the API server after changes. ## Linked Issues <!-- N/A --> ## Additional Context Pocket iOS dev workflow: `cap`/`capacitor.config` often points at a LAN HTTPS origin; without this allowlist the API rejects those `Origin`/`Referer`/`redirect_uri` bases. Review can stay focused on **`apps/server/src/libs/env.ts`**, **`apps/server/src/utils/origin.ts`**, and wiring in **`app.ts`**, **Stripe**, **auth routes**.
27 lines
757 B
Bash
27 lines
757 B
Bash
DATABASE_URL="postgresql://postgres:example-PAssw0rd-xHjDYR.b7N@db:5432/postgres"
|
|
REDIS_URL="redis://localhost:6379"
|
|
|
|
BETTER_AUTH_SECRET=""
|
|
|
|
AUTH_GOOGLE_CLIENT_ID=""
|
|
AUTH_GOOGLE_CLIENT_SECRET=""
|
|
|
|
AUTH_GITHUB_CLIENT_ID=""
|
|
AUTH_GITHUB_CLIENT_SECRET=""
|
|
|
|
STRIPE_SECRET_KEY=""
|
|
STRIPE_WEBHOOK_SECRET=""
|
|
|
|
CLIENT_URL=""
|
|
API_SERVER_URL=""
|
|
|
|
# Comma-separated browser origins for CORS (/api/*) and Stripe return URLs.
|
|
# Required when the Capacitor dev server uses a LAN IP (see ios/App/App/capacitor.config.json),
|
|
# e.g. ADDITIONAL_TRUSTED_ORIGINS="https://10.0.0.129:5273,https://198.18.0.1:5273"
|
|
|
|
# OTEL_EXPORTER_OTLP_ENDPOINT="http://localhost:4318"
|
|
|
|
GATEWAY_BASE_URL="http://localhost:18080"
|
|
DEFAULT_CHAT_MODEL="openai/gpt-5-mini"
|
|
DEFAULT_TTS_MODEL="microsoft/v1"
|