Repository navigation
fix(invite): add /invite where cloudflare pages reads it - #1895
Conversation
I fixed this twice in the wrong layer. lucky.lucassantana.tech is served by Cloudflare Pages (project lucky-webapp, deploy-frontend-cf.yml), not by Vercel and not by the homelab nginx behind the tunnel. So neither the vercel.json redirect (#1889) nor the nginx location block (#1893) applied to the public site, and /invite kept returning 200 with the SPA. What gave it away: the live response carries a CSP allowing static.cloudflareinsights.com, which appears only in packages/frontend/public/_headers. The nginx config serves a different CSP, so the request was never reaching it. Meanwhile lucky-api.lucassantana.tech DOES go through the tunnel, and already returns the correct 302 with permissions=3165184, so the backend handler and the nginx work from #1893 are both fine and stay. _redirects rules are evaluated top to bottom, so /invite is placed above the SPA catch-all, which is what was swallowing it. Points at the backend rather than Discord directly so the utm_* attribution logging still runs. Verified the file lands in packages/frontend/dist after a build, which is the directory `wrangler pages deploy` uploads.
|
Warning Review limit reached
Next review available in: 1 minute Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Failed to generate code suggestions for PR |
|
Size Change: 0 B Total Size: 498 kB ℹ️ View Unchanged
|
There was a problem hiding this comment.
No issues found across 1 file
Auto-approved: Adds a single redirect rule to fix the /invite route being swallowed by the SPA catch-all. The change is bounded (one route, one rule) and clearly beneficial as a focused bug fix.
Re-trigger cubic
|
🤖 I have created a release *beep* *boop* --- <details><summary>2.38.0</summary> ## [2.38.0](v2.37.3...v2.38.0) (2026-07-27) ### Features * **bot:** add /ticket-setup for support category and agent role ([#1863](#1863)) ([3f4af39](3f4af39)) * **frontend:** per-action loading and connection gating on music controls ([#1866](#1866)) ([2dda60f](2dda60f)) * **frontend:** show stale progress when music SSE lags ([#1867](#1867)) ([4952e73](4952e73)) * **music:** surface recommendationReason in nowplaying and queue ([#1864](#1864)) ([960fd62](960fd62)) * **ops:** blue/green zero-downtime deploys — Phase 1 web tier ([#1786](#1786)) ([f5f7597](f5f7597)) ### Bug Fixes * **docker:** make compose stack boot from a fresh .env ([#1674](#1674)) ([babe0ef](babe0ef)) * **docker:** treat an empty db password as missing in compose guards ([#1881](#1881)) ([718c0ad](718c0ad)) * **frontend:** make landing page usable at mobile widths ([#1865](#1865)) ([6190350](6190350)) * **frontend:** stop hero grid columns overflowing on narrow viewports ([#1874](#1874)) ([ce5cea0](ce5cea0)) * **invite:** add /invite where cloudflare pages reads it ([#1895](#1895)) ([0528f66](0528f66)) </details> --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
## Summary Nothing in the repo said which of the three independent hosting layers (Cloudflare Pages, Cloudflare Tunnel + homelab nginx, legacy Vercel preview) serves which host, or which config file governs each. Fixing the /invite redirect took three PRs (#1889, #1893, #1895) before landing in the right file. - Added a "Deployment & hosting" section to docs/ARCHITECTURE.md: the host/layer/config table, the CSP trick for identifying which layer answered a request, and the nginx.conf/_redirects gotchas that cost time before. - Added a one-line pointer to that section at the top of nginx.conf and _redirects. - vercel.json and _headers intentionally left untouched: vercel.json is strict JSON with no safe comment syntax, and _headers' Cloudflare Pages comment support isn't proven in this repo the way _redirects' is (its existing comment block already works in production - _headers has none to point to as precedent). Not worth guessing on a live config file for a one-line pointer when docs/ARCHITECTURE.md already names both files. ## Test plan - [x] Read-only doc/comment change, no code paths touched - [x] nginx.conf comment uses `#`, the format nginx already uses throughout this file - [x] _redirects comment extends the file's own pre-existing `#` comment block, proven safe since it's already live in production Closes #1924 <!-- This is an auto-generated description by cubic. --> --- ## Summary by cubic Documents which of the three hosting layers (Cloudflare Pages, Cloudflare Tunnel + homelab nginx, legacy Vercel preview) serves which host and which config file governs each, so fixes like `/invite` land in the right file instead of taking three PRs. - Adds a Deployment & hosting section to `docs/ARCHITECTURE.md` with the host/layer/config table, the CSP trick for identifying which layer answered, the `nginx.conf` `/api`-proxying rule plus its `/invite`, `/webhook/`, `/webhooks/` exceptions, and the `_redirects` top-to-bottom gotcha. - Adds pointers to that section at the top of `nginx.conf` and `_redirects`. - Read-only change; leaves `vercel.json` and `_headers` untouched. Closes #1924. <sup>Written for commit 4b401a0. Summary will update on new commits.</sup> <a href="https://cubic.dev/pr/LucasSantana-Dev/Lucky/pull/2253?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. -->



Third attempt at #1888, and the first one aimed at the layer that actually serves the site. Correcting myself: the previous two fixes were in the wrong place.
Where the traffic really goes
lucky.lucassantana.techlucky-webapp,deploy-frontend-cf.yml)packages/frontend/public/_redirectslucky-api.lucassantana.technginx/nginx.confSo
vercel.json(#1889) applies to neither, and the nginx block (#1893) applies only to the API host. The public site kept returning200with the SPA.How I confirmed it rather than guessing again
The live response for
/invitecarries:That
static.cloudflareinsights.comallowance exists only inpackages/frontend/public/_headers.nginx/nginx.confserves a different CSP without it, so the request was demonstrably never reaching nginx.Meanwhile the API host already works, which confirms #1893 landed correctly:
The change
_redirectsrules are evaluated top to bottom, and the existing/* /index.html 200catch-all matched/invitefirst — that is the mechanism that swallowed every invite click.Points at the backend rather than Discord directly, so the
[invite] clickutm logging from #1893 still runs.Nothing from #1893 is reverted: the nginx block and the shared
BOT_INVITE_PERMISSIONSconstant are what make the destination correct.Verification
_redirectsconfirmed present inpackages/frontend/dist/afternpm run build:frontend, which is the directorywrangler pages deployuploads.Will verify against production once the Pages deploy runs.
Summary by cubic
Adds a Cloudflare Pages
_redirectsrule so/invitenow 302s to the backend, fixing the route being swallowed by the SPA. Keeps UTM tracking by routing through the API.Written for commit fbb7674. Summary will update on new commits.