(port: number)
| 170 | // poison those links (the request origin is only trusted for the CSRF/ |
| 171 | // `trustedOrigins` check, which is same-origin-safe; see better-auth.ts). |
| 172 | const resolveWebBaseUrl = (port: number): string => { |
| 173 | const resolved = resolvePublicOrigin({ |
| 174 | explicit: process.env.EXECUTOR_WEB_BASE_URL, |
| 175 | env: process.env, |
| 176 | }); |
| 177 | if (resolved) return resolved; |
| 178 | const fallback = `http://localhost:${port}`; |
| 179 | // A deployed instance with no detectable origin mints localhost links — warn |
| 180 | // once (unless local dev/test) so the operator sets the variable. |
| 181 | if (!warnedNoPublicUrl && shouldWarnMissingPublicOrigin(process.env.NODE_ENV)) { |
| 182 | warnedNoPublicUrl = true; |
| 183 | console.warn(missingPublicOriginWarning({ varName: "EXECUTOR_WEB_BASE_URL", fallback })); |
| 184 | } |
| 185 | return fallback; |
| 186 | }; |
| 187 | |
| 188 | export const loadConfig = (): SelfHostConfig => { |
| 189 | const port = Number.parseInt(process.env.PORT ?? "4788", 10); |
no test coverage detected