diff --git a/start.sh b/start.sh index d6251ac..2930ca4 100644 --- a/start.sh +++ b/start.sh @@ -77,8 +77,11 @@ export NO_OPENAPI="True" # Proxy settings for Cloudron's reverse proxy export LITELLM_PROXY_BASE_URL="https://${CLOUDRON_APP_DOMAIN}" -# Allow requests from Cloudron's Open WebUI, LobeChat, etc. -export LITELLM_CORS_ALLOWED_ORIGINS="${CLOUDRON_WEB_ORIGIN:-*}" +# CORS: lock browser access to the co-op's own chat origin. The gateway is +# called server-to-server (chat → portal → gateway) and by member API keys +# (curl/SDKs, not browsers), so no wildcard is needed. A `*` here (the old +# fallback) would let any website's JS hit the gateway. +export LITELLM_CORS_ALLOWED_ORIGINS="https://chat.inference.coop" echo "PostgreSQL: ${CLOUDRON_POSTGRESQL_HOST}:${CLOUDRON_POSTGRESQL_PORT}" echo "Redis: ${CLOUDRON_REDIS_HOST}:${CLOUDRON_REDIS_PORT}"