diff --git a/docs/deployment-readiness.md b/docs/deployment-readiness.md index 25fdfe2..2cc7c99 100644 --- a/docs/deployment-readiness.md +++ b/docs/deployment-readiness.md @@ -25,9 +25,10 @@ The readiness endpoint fails in production if the database cannot be reached or ## Frontend: Vercel or Equivalent -Required frontend environment variables: - -- `VITE_API_URL=https://your-backend.example.com` +Production browser requests use the same-origin `/api` path. `frontend/vercel.json` +proxies that path to the Railway API so secure session and CSRF cookies are not +dependent on third-party-cookie behavior. `VITE_API_URL` is only used for local +development when the API runs on a different origin. Build command: diff --git a/frontend/src/api.ts b/frontend/src/api.ts index a5bf101..eefda19 100644 --- a/frontend/src/api.ts +++ b/frontend/src/api.ts @@ -1,6 +1,11 @@ import axios from 'axios'; -export const API_BASE_URL = import.meta.env.VITE_API_URL ?? 'http://localhost:8000'; +// Production browser traffic stays on the Vercel origin and is forwarded to +// Railway by vercel.json. This keeps the HttpOnly session and readable CSRF +// cookies first-party instead of relying on third-party cookie support. +export const API_BASE_URL = import.meta.env.PROD + ? '/api' + : import.meta.env.VITE_API_URL ?? 'http://localhost:8000'; export const api = axios.create({ baseURL: API_BASE_URL, diff --git a/frontend/vercel.json b/frontend/vercel.json index 1e13e98..985976d 100644 --- a/frontend/vercel.json +++ b/frontend/vercel.json @@ -11,9 +11,15 @@ { "key": "X-Frame-Options", "value": "DENY" }, { "key": "Referrer-Policy", "value": "no-referrer" }, { "key": "Permissions-Policy", "value": "camera=(), microphone=(), geolocation=()" }, - { "key": "Content-Security-Policy", "value": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; img-src 'self' data:; style-src 'self' 'unsafe-inline'; script-src 'self'; connect-src 'self' https://api.replace-with-approved-host.example; upgrade-insecure-requests" } + { "key": "Content-Security-Policy", "value": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; img-src 'self' data:; style-src 'self' 'unsafe-inline'; script-src 'self'; connect-src 'self'; upgrade-insecure-requests" } ] } ], - "rewrites": [{ "source": "/(.*)", "destination": "/index.html" }] + "rewrites": [ + { + "source": "/api/:path*", + "destination": "https://topstep-mvp-bot-production.up.railway.app/:path*" + }, + { "source": "/(.*)", "destination": "/index.html" } + ] }