The web interface always talks to the address it was loaded from — the nginx in the container forwards /v1/ and /auth/v1/ internally. That’s why an address on your local network works without a rebuild.
Set the address for the backend
For CORS, the sign-in redirects and invitation links to work, set the same address for the backend when you start:
WHO2BE_PUBLIC_URL=http://192.168.1.42:5173 docker compose up -d --wait
Then open http://192.168.1.42:5173 from any device on the network.
Outside a trusted network
This setup isn’t enough for that. You need the hardened setup with TLS — with automatic HTTPS, backups and a runbook, described in the deploy/hetzner (external site) directory.