Skip to content

Allow local ApplyOS hosts in Next.js dev - #2

Merged
bmoir23 merged 1 commit into
mainfrom
bmoir23-cloud/allow-dev-origins-d043
Oct 4, 2026
Merged

bmoir23 merged 1 commit into
mainfrom
bmoir23-cloud/allow-dev-origins-d043

Conversation

@bmoir23

@bmoir23 bmoir23 commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Summary

Next.js was blocking dev assets when the app was opened on applyos.me, which is the only origin Clerk production keys accept. allowedDevOrigins now includes that host along with localhost.

Test plan

  • Start pnpm dev and open the app on an allowed host
  • Confirm the sign-in page loads Clerk instead of failing on a blocked dev origin
Open in Web Open in Cursor 

Summary by Sourcery

Bug Fixes:

  • Allow Next.js development assets to load when the app is accessed through the ApplyOS hosts required by Clerk production authentication.

Clerk production keys only accept the applyos.me origin, and Next.js blocks
dev assets from that host unless it is listed in allowedDevOrigins.

Co-authored-by: Brian Moir <bmoir23@users.noreply.github.com>
@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates Next.js dev configuration to permit assets when the app is accessed through supported ApplyOS domains or local hosts, allowing Clerk sign-in to load during development.

Flow diagram for allowed Next.js development origins

flowchart LR
    Browser[Browser on ApplyOS or local host] --> NextDev[Next.js development server]
    NextDev --> OriginCheck{Origin allowed}
    OriginCheck -->|applyos.me or dev.applyos.me| DevAssets[Serve development assets]
    OriginCheck -->|127.0.0.1 or localhost| DevAssets
    DevAssets --> Clerk[Clerk sign-in loads]
Loading

File-Level Changes

Change Details Files
Expand Next.js development-origin allowlisting for ApplyOS and local hosts.
  • Add applyos.me and dev.applyos.me to allowed development origins.
  • Retain localhost and 127.0.0.1 as allowed origins.
  • Document the need to load Clerk production-key assets during local development.
next.config.ts

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@bmoir23
bmoir23 marked this pull request as ready for review October 4, 2026 02:36
Copilot AI balanced review requested due to automatic review settings October 4, 2026 02:36
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
applyos b46243d Oct 04 2026, 02:36 AM

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@bmoir23
bmoir23 merged commit 7167140 into main Oct 4, 2026
4 of 6 checks passed
@bmoir23
bmoir23 deleted the bmoir23-cloud/allow-dev-origins-d043 branch October 4, 2026 02:37

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Needs a human reviewer. If the allowlist is wrong, a Next.js development server may accept requests or serve development assets to an unintended origin, potentially exposing local development data or enabling cross-origin access. Reverting restores the previous blocking behavior, but any information exposed while the setting was active cannot be recovered.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Cursor Bugbot was not present after the first check poll, no approval policy required human review, and there is no unresolved Bugbot finding on this head. I am approving based on those configured signals.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants