fix: MinIO CORS blocking browser uploads, changelog admin-only

- MinIO had no CORS config at all, so the browser's direct PUT to a
  presigned URL (cross-origin: app on :3001/:3000, storage on :9000)
  was blocked outright. Added MINIO_API_CORS_ALLOW_ORIGIN — "*" in
  dev, the app's own origin in prod. Verified end-to-end: photo
  upload now succeeds with zero console errors.
- Removed the public /changelog page and its account-menu link —
  changelog is admin-only now (/admin/changelog).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Arnaud
2026-07-12 12:33:53 +02:00
parent 321507b570
commit ccc41a2018
6 changed files with 9 additions and 28 deletions
+4
View File
@@ -27,6 +27,10 @@ services:
environment:
MINIO_ROOT_USER: ${MINIO_ROOT_USER}
MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD}
# The browser PUTs photo uploads directly to MinIO using a presigned URL
# (STORAGE_PUBLIC_URL) — without CORS allowed for that origin, the browser
# blocks the request. Restricted to the app's own origin, not "*".
MINIO_API_CORS_ALLOW_ORIGIN: ${BETTER_AUTH_URL}
volumes:
- minio_data:/data
command: server /data --console-address ":9001"