mirror of
https://github.com/bytedance/deer-flow.git
synced 2026-08-09 06:18:57 +00:00
Opening the dev stack on a LAN address or a proxied hostname serves the SSR HTML but never hydrates: Next.js answers /_next/*, /__nextjs_font/*, and HMR with 403 for any host it was not started on. The page renders, so it looks up — but no client handler is attached, and the login form's onSubmit never fires. It reads as "login is broken" rather than as an asset problem, and the only clue is a warning in the dev-server log. Wire Next's allowedDevOrigins to a new DEER_FLOW_DEV_ALLOWED_ORIGINS env var. Unset by default, so the localhost-only default is unchanged; it is also dev-only, as Next ignores allowedDevOrigins in production builds. Entries are reduced to the bare host that allowedDevOrigins matches against, since an entry pasted from the address bar as "http://192.168.1.10:2026" would otherwise match nothing and leave the operator with the same 403 they were trying to fix. Reported in #54 and #203. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>