fix: MinIO CORS blocking browser uploads, changelog admin-only

- MinIO had no CORS config at all, so the browser's direct PUT to a
  presigned URL (cross-origin: app on :3001/:3000, storage on :9000)
  was blocked outright. Added MINIO_API_CORS_ALLOW_ORIGIN — "*" in
  dev, the app's own origin in prod. Verified end-to-end: photo
  upload now succeeds with zero console errors.
- Removed the public /changelog page and its account-menu link —
  changelog is admin-only now (/admin/changelog).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Arnaud
2026-07-12 12:33:53 +02:00
parent 321507b570
commit ccc41a2018
6 changed files with 9 additions and 28 deletions
+4
View File
@@ -40,6 +40,10 @@ services:
environment:
MINIO_ROOT_USER: minioadmin
MINIO_ROOT_PASSWORD: minioadmin
# The browser PUTs photo uploads directly to MinIO using a presigned URL,
# which is cross-origin from the Next.js app (different port) — without
# this, the browser blocks the request with a CORS error.
MINIO_API_CORS_ALLOW_ORIGIN: "*"
ports:
- "9000:9000"
- "9001:9001"