You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
add Vercel /api/* rewrite to backend API host to prevent frontend-host 404 during OAuth
normalize backend frontend origin parsing using a shared helper
use primary frontend origin for OAuth and Last.fm redirects when multiple origins are configured
Validation
npm run test --workspace=packages/backend -- tests/integration/routes/auth.test.ts tests/integration/routes/lastfm.test.ts
Notes
api.lucky.lucassantana.tech DNS/tunnel was configured, but TLS handshake is not available with current cert coverage; production API target remains lucky-api.lucassantana.tech for now.
Summary by CodeRabbit
Release Notes
Bug Fixes
Resolved OAuth and Last.fm redirect failures when configuring multiple frontend domains; redirects now use the primary domain.
Fixed 404 errors on API requests by implementing proper forwarding to the backend API service.
Documentation
Added guidance on configuring multiple frontend domains using comma-separated values and how each service handles multi-domain setups.
This PR centralizes frontend origin configuration management by introducing helper utilities to parse WEBAPP_FRONTEND_URL (supporting comma-separated values) and retrieve the primary origin for OAuth/API redirects. It also adds Vercel route proxying to forward API requests to an external backend.
New module introducing getFrontendOrigins() (returns array of parsed comma-separated origins) and getPrimaryFrontendUrl() (returns first origin) with fallback to http://localhost:5173.
Updated to use centralized getPrimaryFrontendUrl() instead of direct environment variable access for OAuth/Last.fm redirect URL resolution.
Middleware CORS Configuration packages/backend/src/middleware/index.ts
Refactored to use centralized getFrontendOrigins() helper for origin validation instead of inline environment variable parsing.
Documentation README.md, CHANGELOG.md
Added documentation clarifying multi-origin WEBAPP_FRONTEND_URL format (comma-separated) and CHANGELOG entries documenting the primary origin behavior for redirects and API proxying.
Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.
Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name
Status
Explanation
Title check
✅ Passed
The title accurately summarizes the main changes: preventing frontend-host OAuth 404 errors via Vercel rewrite and normalizing frontend origins handling across the backend.
Description Check
✅ Passed
Check skipped - CodeRabbit’s high-level summary is enabled.
✏️ Tip: You can configure your own custom pre-merge checks in the settings.
✨ Finishing Touches
📝 Generate docstrings (stacked PR)
📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
Create PR with unit tests
Post copyable unit tests in a comment
Commit unit tests in branch fix/auth-api-host-and-cors
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
/api/*rewrite to backend API host to prevent frontend-host 404 during OAuthValidation
npm run test --workspace=packages/backend -- tests/integration/routes/auth.test.ts tests/integration/routes/lastfm.test.tsNotes
api.lucky.lucassantana.techDNS/tunnel was configured, but TLS handshake is not available with current cert coverage; production API target remainslucky-api.lucassantana.techfor now.Summary by CodeRabbit
Release Notes
Bug Fixes
Documentation