React-Frontend: Profilseite und Statistik, Dev-Proxy-Fix
- UserPage mit Profilkopf, Einstellungen (Avatar, Name, Konto löschen) und Nutzer-Feed im unveränderten Markup - StatsPage mit Kacheln und Balken wie bisher - Feed-Container wählbar (section/div) wie im alten Markup - Vite-Proxy mit changeOrigin: false -- sonst scheitert jeder POST im Dev-Betrieb am Origin-Check Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TiXsPUqw7oeomZ8wZrQW5q
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
ca65ddcacc
commit
728ac9b45e
@@ -4,14 +4,19 @@ import react from "@vitejs/plugin-react";
|
||||
// Im Dev-Betrieb läuft das Go-Backend separat (siehe dev.env, Port 8081).
|
||||
// Vite reicht /api und /static dorthin durch -- für den Browser bleibt alles
|
||||
// eine Origin, Session-Cookie und Origin-Check funktionieren unverändert.
|
||||
//
|
||||
// changeOrigin: false ist Pflicht: die Kurzform (nur URL) setzt es auf true
|
||||
// und schreibt den Host-Header auf das Backend um. Dann passt der Origin des
|
||||
// Browsers nicht mehr zum Host und checkOrigin weist jeden POST als CSRF ab.
|
||||
const backend = process.env.KVER_BACKEND ?? "http://127.0.0.1:8081";
|
||||
const proxy = { target: backend, changeOrigin: false };
|
||||
|
||||
export default defineConfig({
|
||||
plugins: [react()],
|
||||
server: {
|
||||
proxy: {
|
||||
"/api": backend,
|
||||
"/static": backend,
|
||||
"/api": proxy,
|
||||
"/static": proxy,
|
||||
},
|
||||
},
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user