fix: MinIO CORS blocking browser uploads, changelog admin-only
- MinIO had no CORS config at all, so the browser's direct PUT to a presigned URL (cross-origin: app on :3001/:3000, storage on :9000) was blocked outright. Added MINIO_API_CORS_ALLOW_ORIGIN — "*" in dev, the app's own origin in prod. Verified end-to-end: photo upload now succeeds with zero console errors. - Removed the public /changelog page and its account-menu link — changelog is admin-only now (/admin/changelog). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -27,6 +27,10 @@ services:
|
||||
environment:
|
||||
MINIO_ROOT_USER: ${MINIO_ROOT_USER}
|
||||
MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD}
|
||||
# The browser PUTs photo uploads directly to MinIO using a presigned URL
|
||||
# (STORAGE_PUBLIC_URL) — without CORS allowed for that origin, the browser
|
||||
# blocks the request. Restricted to the app's own origin, not "*".
|
||||
MINIO_API_CORS_ALLOW_ORIGIN: ${BETTER_AUTH_URL}
|
||||
volumes:
|
||||
- minio_data:/data
|
||||
command: server /data --console-address ":9001"
|
||||
|
||||
Reference in New Issue
Block a user