e661e3738f5b02d7c7c409704b61e609c871fffb
A light install is reached at localhost on the machine running it, so PUBLIC_URL has exactly one right answer. setup.sh required it with a re-prompt loop; under the light profile it now defaults to http://localhost:$PORT. The macOS installer already did this — this is parity, and it removes the one prompt in a light run whose answer a non-technical user could not be expected to produce. setup_mac_light.sh also wrote PUBLIC_BUILD_ENV="development", justified in a comment as "what makes plain http://localhost work". That is no longer true, and the cost of it is not small. IS_DEV_BUILD gates exactly three things: origin validation already off regardless — ALLOW_ANY_ORIGIN defaults to true password rules validatePassword is skipped entirely on change-password rate limiting the limiter returns next() before doing anything So the only live effects were losing the last two, for a benefit that another default already provided. It now writes "production", matching setup.sh. Nothing about localhost needed relaxing: browsers treat http://localhost as a secure context, so passkeys, getUserMedia and the clipboard all work over plain HTTP, and passkeys in particular derive their RP ID from the request origin rather than a configured domain. That last point is the boundary worth knowing: http://192.168.x.x is NOT a secure context, so reaching a light install from another device means putting an HTTPS proxy in front of it. Recorded in the comments at both prompts. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Description
No description provided
42 MiB
Languages
TypeScript
90.9%
Shell
4.7%
JavaScript
4.1%
CSS
0.2%
HTML
0.1%