diff --git a/.changes/pwa-self-hosted-cors-default.md b/.changes/pwa-self-hosted-cors-default.md
new file mode 100644
index 000000000..48280a8ec
--- /dev/null
+++ b/.changes/pwa-self-hosted-cors-default.md
@@ -0,0 +1,9 @@
+---
+type: fix
+area: pwa
+---
+
+Self-hosted web backends started without `CLIENT_URL` now allow the documented
+`http://localhost:4333` origin instead of the retired public demo URL, so a
+manual (non-Docker) deployment no longer fails every provider request with a
+CORS error.
diff --git a/apps/web-backend/src/app/web-backend-app.ts b/apps/web-backend/src/app/web-backend-app.ts
index 75ebc8e61..f4994c63a 100644
--- a/apps/web-backend/src/app/web-backend-app.ts
+++ b/apps/web-backend/src/app/web-backend-app.ts
@@ -575,10 +575,13 @@ function getClientOrigins(): string[] {
return configured;
}
+ // Production default matches the documented self-hosted setup
+ // (docker/docker-compose.yml maps the PWA to port 4333). The Docker image
+ // sets CLIENT_URL explicitly; this fallback only covers manual runs.
return process.env['NODE_ENV'] === 'development' ||
process.env['NODE_ENV'] === 'dev'
? ['http://localhost:4200']
- : ['https://iptvnator.vercel.app'];
+ : ['http://localhost:4333'];
}
function getQueryString(req: Request, key: string): string | undefined {
diff --git a/apps/web/src/index.html b/apps/web/src/index.html
index dc036d8b7..a70a34f96 100644
--- a/apps/web/src/index.html
+++ b/apps/web/src/index.html
@@ -12,7 +12,7 @@
/>
-
+