Skip to content

fix(auth): prevent frontend-host oauth 404 and normalize frontend origins - #128

Merged
LucasSantana-Dev merged 1 commit into
mainfrom
fix/auth-api-host-and-cors
Mar 10, 2026
Merged

LucasSantana-Dev merged 1 commit into
mainfrom
fix/auth-api-host-and-cors

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Mar 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • add Vercel /api/* rewrite to backend API host to prevent frontend-host 404 during OAuth
  • normalize backend frontend origin parsing using a shared helper
  • use primary frontend origin for OAuth and Last.fm redirects when multiple origins are configured

Validation

  • npm run test --workspace=packages/backend -- tests/integration/routes/auth.test.ts tests/integration/routes/lastfm.test.ts

Notes

  • api.lucky.lucassantana.tech DNS/tunnel was configured, but TLS handshake is not available with current cert coverage; production API target remains lucky-api.lucassantana.tech for now.

Summary by CodeRabbit

Release Notes

  • Bug Fixes

    • Resolved OAuth and Last.fm redirect failures when configuring multiple frontend domains; redirects now use the primary domain.
    • Fixed 404 errors on API requests by implementing proper forwarding to the backend API service.
  • Documentation

    • Added guidance on configuring multiple frontend domains using comma-separated values and how each service handles multi-domain setups.

@vercel

vercel Bot commented Mar 10, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment Mar 10, 2026 2:18am

@netlify

netlify Bot commented Mar 10, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for regal-bunny-0c8efe ready!

Name Link
🔨 Latest commit fb1f83b
🔍 Latest deploy log https://app.netlify.com/projects/regal-bunny-0c8efe/deploys/69af7f29afec630008c2dfdf
😎 Deploy Preview https://deploy-preview-128--regal-bunny-0c8efe.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Mar 10, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

This PR centralizes frontend origin configuration management by introducing helper utilities to parse WEBAPP_FRONTEND_URL (supporting comma-separated values) and retrieve the primary origin for OAuth/API redirects. It also adds Vercel route proxying to forward API requests to an external backend.

Changes

Cohort / File(s) Summary
Frontend Origin Utilities
packages/backend/src/utils/frontendOrigin.ts
New module introducing getFrontendOrigins() (returns array of parsed comma-separated origins) and getPrimaryFrontendUrl() (returns first origin) with fallback to http://localhost:5173.
Backend Route OAuth Updates
packages/backend/src/routes/auth.ts, packages/backend/src/routes/authCallback.ts, packages/backend/src/routes/lastfm.ts
Updated to use centralized getPrimaryFrontendUrl() instead of direct environment variable access for OAuth/Last.fm redirect URL resolution.
Middleware CORS Configuration
packages/backend/src/middleware/index.ts
Refactored to use centralized getFrontendOrigins() helper for origin validation instead of inline environment variable parsing.
Documentation
README.md, CHANGELOG.md
Added documentation clarifying multi-origin WEBAPP_FRONTEND_URL format (comma-separated) and CHANGELOG entries documenting the primary origin behavior for redirects and API proxying.
Vercel Deployment Configuration
vercel.json
Added rewrites configuration to proxy /api/:path* requests to https://lucky-api.lucassantana.tech/api/:path* for external backend routing.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

Suggested labels

ci, size/m

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately summarizes the main changes: preventing frontend-host OAuth 404 errors via Vercel rewrite and normalizing frontend origins handling across the backend.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/auth-api-host-and-cors

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@sonarqubecloud

Copy link
Copy Markdown

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
0.0% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

This branch was successfully deployed

1 active deployment
Preview — fb1f83bb Deployed Mar 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant