import os from flask import Flask from flask_cors import CORS from .config import Config from .db import init_db def create_app() -> Flask: app = Flask(__name__, instance_relative_config=True) app.config.from_object(Config) os.makedirs(app.instance_path, exist_ok=True) os.makedirs(Config.UPLOAD_DIR, exist_ok=True) # Frontend runs on a different origin (vite dev server) during # development; lock this down to that origin in production. Auth now # relies on a session cookie, so credentials must be allowed - and with # supports_credentials, the origin allowlist can't be "*", it has to be # this one explicit origin (flask-cors enforces that). CORS( app, resources={r"/api/*": {"origins": Config.CORS_ORIGIN}, r"/auth/*": {"origins": Config.CORS_ORIGIN}}, supports_credentials=True, ) init_db(Config.DATABASE_PATH) from .auth_routes import bp as auth_bp from .routes import bp as api_bp app.register_blueprint(api_bp, url_prefix="/api") app.register_blueprint(auth_bp, url_prefix="/auth") return app