fix: remove the pickup and invoice notes from checkout; document R2 CORS
All checks were successful
Build and deploy / Validate source (push) Successful in 6s
Build and deploy / Integration suite on a real stack (push) Successful in 2m15s
Build and deploy / Secret scan and release gate (push) Successful in 6s
Build and deploy / Publish images (push) Successful in 1m41s

The pickup notice under the delivery options and the invoice and retention
note under the purchase summary are gone. PORTAINER.md records the R2 CORS
policy the browser's direct uploads need: without it the preflight is
refused and checkout fails with a NetworkError before payment.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-28 11:10:52 -03:00
parent 275ebf72c4
commit a1877bdf0a
3 changed files with 18 additions and 9 deletions

View File

@@ -93,6 +93,24 @@ as `dtf_prod_database_url_v1`, then place only those names in the corresponding
Credential values must never be entered into Git, `portainer.env`, or Gitea
workflow variables.
**R2 CORS.** The Site uploads artwork straight from the browser to the bucket
with presigned `PUT` requests, so the bucket must allow the Site's origin.
Without it the preflight is refused (403) and the Site shows "NetworkError
when attempting to fetch resource" at checkout (found 2026-09-28). In the
Cloudflare dashboard, R2 → the bucket → Settings → CORS policy:
```json
[
{
"AllowedOrigins": ["https://<SITE_DOMAIN>", "https://<KANBAN_DOMAIN>"],
"AllowedMethods": ["PUT", "GET", "HEAD"],
"AllowedHeaders": ["content-type"],
"ExposeHeaders": ["ETag"],
"MaxAgeSeconds": 3600
}
]
```
## 3. Create the stack once
In Portainer select **Stacks → Add stack → Git repository**:

View File

@@ -668,7 +668,6 @@ h1 em{font-style:normal;color:var(--laranja)}
.cbts button:disabled{opacity:.4;cursor:not-allowed}
.cbts .sec{background:#fff;color:var(--tx);border:1px solid var(--linha);font-weight:600}
.cbts .sec:hover{background:#fff;border-color:var(--laranja);color:var(--laranja)}
.carr .obs{font-size:11px;color:var(--fraco);margin-top:11px;line-height:1.5}
.carro{position:relative;margin-top:22px}
.trilho{display:flex;gap:14px;overflow-x:auto;scroll-snap-type:x mandatory;
@@ -1192,7 +1191,6 @@ footer a:hover{color:var(--laranja2)}
</div>
<p class="err" id="eEnd"></p>
</div>
<p class="avisoE" id="avisoE"></p>
</div>
</div>
</div>
@@ -1205,9 +1203,6 @@ footer a:hover{color:var(--laranja2)}
<button id="bPagar">Ir para o pagamento</button>
<button id="bMais" class="sec">Continuar comprando</button>
</div>
<p class="obs">A nota fiscal sai no CNPJ informado. O arquivo fica guardado por 30 dias;
depois disso, um novo pedido precisa do arquivo de novo. O histórico do pedido
continua disponível na sua conta.</p>
</aside>
</div>

View File

@@ -104,10 +104,6 @@ function pintaEntrega(){
$('cep').classList.toggle('on', entrega.tipo==='frete');
$('vFrete').textContent = entrega.tipo!=='frete' ? '—'
: entrega.cotado ? rs(entrega.valor) : 'a cotar';
$('avisoE').innerHTML = entrega.tipo==='retira'
? 'DTF é impresso depois que você paga. Avisamos no WhatsApp quando estiver '+
'<b>pronto para retirar</b> — não venha antes do aviso.'
: '';
$('bPagar').disabled = !entrega.cotado || !clienteOk() || !enderecoOk() || !cartPodeEnviar();
$('eEnd').textContent = entrega.tipo==='frete' && entrega.cotado && !enderecoOk()
? 'Preencha o endereço de entrega para seguir.' : '';