diff --git a/.env b/.env index 9869d87..5bcd7a6 100644 --- a/.env +++ b/.env @@ -75,7 +75,7 @@ MERCURE_JWT_SECRET=!ChangeThisMercureJWTSignedBySymfonySecretKey! MERCURE_PUBLISHER_JWT_TOKEN=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJtZXJjdXJlIjp7InB1Ymxpc2giOlsiKiJdfX0.E5b7ma4k-kA7lVGOQtICh7r2sspwX4G1iOhwtbxHQck MERCURE_SUBSCRIBER_JWT_TOKEN=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJtZXJjdXJlIjp7InN1YnNjcmliZSI6WyIqIl19fQ.mwSAjvbm6vOnjMoRSHMdcqapNCwyGZs1s57uLK4T3UM # CORS allowed origins (default) -MERCURE_CORS_ALLOWED_ORIGINS="*" +MERCURE_CORS_ALLOWED_ORIGINS="https://escapepage.com https://escapepage.dev" # Base URL for Mercure topics. MERCURE_TOPIC_BASE=https://escapepage.com ###< mercure ### diff --git a/.env.prod b/.env.prod index 46d111d..e6d12e3 100644 --- a/.env.prod +++ b/.env.prod @@ -21,7 +21,7 @@ SITE_BASE_URL=https://escapepage.com MERCURE_JWT_SECRET=55UtgFXsZu09TSTdeIA7ljK4HUo9DLkRzEB7MD5tqOLjRfAb MERCURE_PUBLISHER_JWT_TOKEN=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJtZXJjdXJlIjp7InB1Ymxpc2giOlsiKiJdfX0.qMVdzh7buYK78e-gwCQx7v6qCxk1Js83SAEKK-GZSrI MERCURE_SUBSCRIBER_JWT_TOKEN=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJtZXJjdXJlIjp7InN1YnNjcmliZSI6WyIqIl19fQ.OCnRPXfCoke27ntAxby2R5jkgpTZdw83DPq1yhvkLbw -MERCURE_CORS_ALLOWED_ORIGINS="*" +MERCURE_CORS_ALLOWED_ORIGINS="https://escapepage.com" MERCURE_TOPIC_BASE=https://escapepage.com ###< mercure ### diff --git a/docker/compose.yaml b/docker/compose.yaml index 1c40cd0..1db62d1 100644 --- a/docker/compose.yaml +++ b/docker/compose.yaml @@ -106,13 +106,9 @@ services: MERCURE_CORS_ALLOWED_ORIGINS: ${MERCURE_CORS_ALLOWED_ORIGINS} MERCURE_PUBLISH_ALLOWED_ORIGINS: ${MERCURE_CORS_ALLOWED_ORIGINS} MERCURE_EXTRA_DIRECTIVES: | - cors_origins "*" - publish_origins "*" + cors_origins ${MERCURE_CORS_ALLOWED_ORIGINS} + publish_origins ${MERCURE_CORS_ALLOWED_ORIGINS} anonymous - # Add explicit CORS headers for safety - header Access-Control-Allow-Origin "*" - header Access-Control-Allow-Methods "GET, POST, OPTIONS" - header Access-Control-Allow-Headers "Authorization, Content-Type" ports: - "8090:80" volumes: