default PUBLIC_URL to the tailnet address, not localhost
localhost is wrong on a machine with a tailnet, and quietly so: it works from the machine itself and nowhere else, so the mistake surfaces on the first phone rather than during setup. And PUBLIC_URL is not decoration — gen:index bakes it into the page's OpenGraph tags, the task API hands it to scripts as OFFICER_API_HOST, and the CalDAV profile builder refuses without it. The tailnet is where Officer is actually reached, and it is the perimeter the whole security model rests on now that origin checking is gone. Its address is the honest default. Prefers the MagicDNS name over the raw 100.x address — both work, but the name survives a node being re-registered and is something a person can type. Falls back to localhost with no tailnet, which is right rather than merely tolerable: a machine with no private network has no better address to guess. Suggests http://officer-dev.ts.pastilhas.dev:9000 on this machine. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -505,7 +505,11 @@ if ! skip; then
|
||||
echo " it: the OpenGraph tags baked into the page by 'bun gen:index', the"
|
||||
echo " host the task API hands to scripts, and the CalDAV profile an iPhone"
|
||||
echo " installs — that last one requires https."
|
||||
ask_required ENV_PUBLIC_URL "Public URL" "${ENV_PUBLIC_URL:-http://localhost:${ENV_PORT}}"
|
||||
echo ""
|
||||
echo " Defaulting to this machine's tailnet address, not localhost: the"
|
||||
echo " tailnet is where Officer is actually reached from, and localhost"
|
||||
echo " works from here and nowhere else."
|
||||
ask_required ENV_PUBLIC_URL "Public URL" "${ENV_PUBLIC_URL:-$(default_public_url "$ENV_PORT")}"
|
||||
|
||||
echo ""
|
||||
echo " to write:"
|
||||
|
||||
Reference in New Issue
Block a user