From 51f5691f4577fd84df099c2d4e2b687dd6bd8ef6 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 26 Jun 2026 17:25:31 +0000 Subject: [PATCH] =?UTF-8?q?Corrige=20la=20redirection=20login=20derri?= =?UTF-8?q?=C3=A8re=20un=20reverse=20proxy=20(AUTH=5FURL)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit La redirection vers /login utilisait http://localhost:8413 (ancienne valeur par défaut d'AUTH_URL). On retire ce défaut localhost : AUTH_URL prend la valeur fournie (ex. https://pleinr.ffnancy.fr) et pilote la redirection. Ajout de AUTH_TRUST_HOST=true (confiance aux en-têtes X-Forwarded-*) et l'entrypoint supprime AUTH_URL si vide. Vérifié : la redirection pointe vers le domaine public. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_01XwfhYHzC9hQWPDnQ2p53GL --- .env.example | 6 ++++-- docker-compose.yml | 7 ++++++- docker-entrypoint.sh | 6 ++++++ src/middleware.ts | 2 ++ 4 files changed, 18 insertions(+), 3 deletions(-) diff --git a/.env.example b/.env.example index 3ed7ead..3f31391 100644 --- a/.env.example +++ b/.env.example @@ -16,8 +16,10 @@ POSTGRES_DB=pleinr # persists one automatically. To set it yourself: openssl rand -base64 32 AUTH_SECRET= # Public URL of the app (used by Auth.js for callbacks). -# With docker-compose the app is published on host port 8413 by default. -AUTH_URL=http://localhost:8413 +# Leave EMPTY behind a reverse proxy (Nginx Proxy Manager, Traefik…): Auth.js +# auto-detects it from the Host / X-Forwarded-Proto headers (trustHost). +# Set it only to force a value, e.g. https://pleinr.ffnancy.fr +AUTH_URL= # ---- First admin user (created by the seed script) ---- SEED_ADMIN_EMAIL=admin@plein-r.fr diff --git a/docker-compose.yml b/docker-compose.yml index 40d7434..6668e82 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -41,7 +41,12 @@ services: # Optional: if left empty, the container generates and persists one # automatically (see docker-entrypoint.sh + the app-data volume). AUTH_SECRET: ${AUTH_SECRET:-} - AUTH_URL: ${AUTH_URL:-http://localhost:8413} + # IMPORTANT behind a reverse proxy: set AUTH_URL to your public URL so the + # login redirect points to the right host, e.g. + # AUTH_URL=https://pleinr.ffnancy.fr + AUTH_URL: ${AUTH_URL:-} + # Lets Auth.js trust the X-Forwarded-* headers from the proxy. + AUTH_TRUST_HOST: "true" SEED_ON_START: ${SEED_ON_START:-true} SEED_ADMIN_EMAIL: ${SEED_ADMIN_EMAIL:-admin@plein-r.fr} SEED_ADMIN_PASSWORD: ${SEED_ADMIN_PASSWORD:-changeme123} diff --git a/docker-entrypoint.sh b/docker-entrypoint.sh index be79c9b..4bd58b5 100644 --- a/docker-entrypoint.sh +++ b/docker-entrypoint.sh @@ -16,6 +16,12 @@ if [ -z "$AUTH_SECRET" ]; then export AUTH_SECRET fi +# If AUTH_URL is empty, unset it so Auth.js derives the public URL from the +# reverse-proxy headers (trustHost) instead of falling back to a hardcoded host. +if [ -z "$AUTH_URL" ]; then + unset AUTH_URL +fi + echo "→ Applying database migrations…" node dist/migrate.cjs diff --git a/src/middleware.ts b/src/middleware.ts index 5eb8dc2..4ad239c 100644 --- a/src/middleware.ts +++ b/src/middleware.ts @@ -2,6 +2,8 @@ import NextAuth from "next-auth"; import { authConfig } from "@/auth.config"; // Edge-safe auth instance (no providers / db) used only to gate routes. +// The redirect target is derived from AUTH_URL (set it to your public URL when +// running behind a reverse proxy, e.g. AUTH_URL=https://pleinr.ffnancy.fr). export const { auth: middleware } = NextAuth(authConfig); export default middleware;