shoc-frontend-new/infra/cdk/lib
Alexandre Brandizzi 8bd89a1f9d feat(infra): proxy /api through CloudFront to the backend
The SPA is served over HTTPS by CloudFront but the backend
(console.seahavenind.com) is HTTP-only, so direct API calls would be blocked
as mixed content. Add a CloudFront /api/* behavior that proxies to the backend
over HTTP (browser <-> CloudFront is HTTPS; CloudFront <-> origin is HTTP) and
set VITE_API_URL=/api (same-origin).

Because distribution-level customErrorResponses are global and would rewrite
real /api 403/404s into the SPA shell, replace them with a viewer-request
CloudFront Function scoped to the S3 (default) behavior that rewrites
extensionless paths to /index.html. /api/* carries no function association.

Backend host is configurable via `-c apiOriginDomain=<host>` (default
console.seahavenind.com).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-02 14:17:27 -03:00
..
frontend-stack.ts feat(infra): proxy /api through CloudFront to the backend 2026-07-02 14:17:27 -03:00