Merge https://localhost and capacitor://localhost into CORS_ALLOWED_ORIGINS and CSRF_TRUSTED_ORIGINS so JWT API calls from native shells pass origin checks without cookie credentials.
Merge https://localhost and capacitor://localhost into CORS_ALLOWED_ORIGINS and CSRF_TRUSTED_ORIGINS so JWT API calls from native shells pass origin checks without cookie credentials.