27eb301086a584e9b29b3e42d3423f3a4f4d7229
The CORS origin check used `NODE_ENV !== 'production'` to decide whether to allow loopback and private-LAN origins. That is not the same question as "is this a dev machine" when NODE_ENV is unset - which is exactly what a fresh Plesk vhost gives you. On such a host the check called it dev and answered `Access-Control-Allow-Origin: http://localhost:<any port>` together with `Access-Control-Allow-Credentials: true`. With the admin session cookie scoped to .nachklang.art, that let any page served from localhost on a signed-in admin's machine read their data cross-origin. admin.config.ts already resolves this correctly - only an explicit 'development' or 'test' relaxes anything, so unset is treated as production - so the CORS check now derives from its `isProd` rather than re-deriving its own answer from NODE_ENV. Two places asking the same question two different ways was the bug. Verified against the built app with a vhost-like environment (no NODE_ENV): before, Origin http://localhost:9999 came back allowed with credentials; after, it is rejected, while https://tickets.nachklang.art and https://admin.nachklang.art are still allowed with credentials. With NODE_ENV=development localhost is still allowed, so local development and the LAN exception for real-device testing are unaffected. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Description
No description provided
Languages
TypeScript
100%