From 432a9043ccf167a8dc1979b802a28d2e348c6b77 Mon Sep 17 00:00:00 2001 From: Anthony Ettinger Date: Thu, 30 Jul 2026 17:36:51 +0000 Subject: [PATCH] fix(cli): default `logicsrc login` to app.logicsrc.com The default was the apex, which runs the marketing app -- so every path the CLI needs (/cli/device/code, /cli/device/token, /cli/authorize, /cli/token, /api/me) returns 404 there. Point it at the host that actually serves them. app.logicsrc.com is now a custom domain on the credentials service with a valid certificate, verified live: /cli/device/code returns 200 and issues a real user code, /api/me returns 401 rather than 404, which is routing working correctly for an unauthenticated request. The apex can forward these paths instead -- that is what the rewrites in apps/logicsrc-web/next.config.ts do -- but that needs a second service deployed to be true, while this needs nothing beyond the domain that already exists. The rewrites stay useful as a convenience; they are no longer load-bearing. $LOGICSRC_API still overrides, unchanged. Co-Authored-By: Claude Opus 5 (1M context) --- plugins/credential-sharing/src/identity.ts | 18 ++++++++++-------- 1 file changed, 10 insertions(+), 8 deletions(-) diff --git a/plugins/credential-sharing/src/identity.ts b/plugins/credential-sharing/src/identity.ts index f2f4695..dc824a6 100644 --- a/plugins/credential-sharing/src/identity.ts +++ b/plugins/credential-sharing/src/identity.ts @@ -39,16 +39,18 @@ export function identityPath(): string { } /** - * Where `logicsrc login` goes when nothing else is configured: the production - * origin, not a generated Railway hostname. + * Where `logicsrc login` goes when nothing else is configured. * - * REQUIRES that logicsrc.com serve the credentials app's CLI routes - * (`/cli/device/code`, `/cli/device/token`, `/cli/authorize`, `/cli/token`, - * `/api/me` — see apps/pwa/src/routes/cli.mjs). Until the apex is pointed at - * that service, login fails with a 404 on the first request; set $LOGICSRC_API - * to the deployment origin to work around it. + * This is the credentials app (apps/pwa) on its own hostname, which is what + * actually serves the CLI routes — /cli/device/code, /cli/device/token, + * /cli/authorize, /cli/token and /api/me (see apps/pwa/src/routes/cli.mjs). + * + * NOT the apex: logicsrc.com runs the marketing app, so every one of those + * paths 404s there. The apex can forward them (see the rewrites in + * apps/logicsrc-web/next.config.ts), but pointing straight at the host that + * serves them needs no proxy hop and no deploy of a second service to work. */ -export const DEFAULT_API_URL = "https://logicsrc.com"; +export const DEFAULT_API_URL = "https://app.logicsrc.com"; /** An explicitly configured API origin, if any. `LOGICSRC_API` is the documented one. */ export function envApiUrl(): string | undefined {