Corrige la redirection login derrière un reverse proxy (AUTH_URL)

La redirection vers /login utilisait http://localhost:8413 (ancienne valeur par
défaut d'AUTH_URL). On retire ce défaut localhost : AUTH_URL prend la valeur
fournie (ex. https://pleinr.ffnancy.fr) et pilote la redirection. Ajout de
AUTH_TRUST_HOST=true (confiance aux en-têtes X-Forwarded-*) et l'entrypoint
supprime AUTH_URL si vide. Vérifié : la redirection pointe vers le domaine public.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XwfhYHzC9hQWPDnQ2p53GL
This commit is contained in:
Claude committed 2026-06-26 17:25:31 +00:00
1 parent e9f5d4ced5
commit 51f5691f45
4 files changed
+18 -3

No files matched your search

+4 -2
View File
@@ -16,8 +16,10 @@ POSTGRES_DB=pleinr
# persists one automatically. To set it yourself: openssl rand -base64 32
AUTH_SECRET=
# Public URL of the app (used by Auth.js for callbacks).
# With docker-compose the app is published on host port 8413 by default.
AUTH_URL=http://localhost:8413
# Leave EMPTY behind a reverse proxy (Nginx Proxy Manager, Traefik…): Auth.js
# auto-detects it from the Host / X-Forwarded-Proto headers (trustHost).
# Set it only to force a value, e.g. https://pleinr.ffnancy.fr
AUTH_URL=
# ---- First admin user (created by the seed script) ----
SEED_ADMIN_EMAIL=admin@plein-r.fr