From a0be588082d3efaa93d666f3210dcfc555cb7581 Mon Sep 17 00:00:00 2001 From: Guido X Jansen Date: Thu, 26 Feb 2026 17:08:56 +0100 Subject: [PATCH] fix(api): remove NEXT_PUBLIC_API_URL to prevent localhost fallback in client bundle (#88) Turbopack was not dead-code-eliminating the typeof window ternary correctly, causing the server-side fallback (http://localhost:3000) to leak into the client bundle. The browser then made cross-origin requests to localhost instead of same-origin relative URLs, producing "NetworkError when attempting to fetch resource" on staging. Replace the fragile process.env pattern with a simple literal: client always uses '' (relative URLs via Caddy), server uses API_INTERNAL_URL. --- src/lib/api/auth-fetch.ts | 5 ++--- src/lib/api/client.ts | 5 ++--- 2 files changed, 4 insertions(+), 6 deletions(-) diff --git a/src/lib/api/auth-fetch.ts b/src/lib/api/auth-fetch.ts index 766e511..53b1cfb 100644 --- a/src/lib/api/auth-fetch.ts +++ b/src/lib/api/auth-fetch.ts @@ -7,10 +7,9 @@ import { refreshSession } from './client' import type { AuthSession } from './types' +/** Client: relative URLs (empty string). Server: internal Docker network URL. */ const API_URL = - typeof window !== 'undefined' - ? (process.env.NEXT_PUBLIC_API_URL ?? '') - : (process.env.API_INTERNAL_URL ?? 'http://localhost:3000') + typeof window === 'undefined' ? (process.env.API_INTERNAL_URL ?? 'http://localhost:3000') : '' interface AuthFetchOptions { method?: 'GET' | 'POST' | 'PUT' | 'DELETE' diff --git a/src/lib/api/client.ts b/src/lib/api/client.ts index 112a8fd..48f2ac6 100644 --- a/src/lib/api/client.ts +++ b/src/lib/api/client.ts @@ -60,10 +60,9 @@ import type { BehavioralFlag, } from './types' +/** Client: relative URLs (empty string). Server: internal Docker network URL. */ const API_URL = - typeof window !== 'undefined' - ? (process.env.NEXT_PUBLIC_API_URL ?? '') - : (process.env.API_INTERNAL_URL ?? 'http://localhost:3000') + typeof window === 'undefined' ? (process.env.API_INTERNAL_URL ?? 'http://localhost:3000') : '' interface FetchOptions { headers?: Record -- 2.51.2