Corrige la redirection login derrière un reverse proxy (AUTH_URL)

La redirection vers /login utilisait http://localhost:8413 (ancienne valeur par
défaut d'AUTH_URL). On retire ce défaut localhost : AUTH_URL prend la valeur
fournie (ex. https://pleinr.ffnancy.fr) et pilote la redirection. Ajout de
AUTH_TRUST_HOST=true (confiance aux en-têtes X-Forwarded-*) et l'entrypoint
supprime AUTH_URL si vide. Vérifié : la redirection pointe vers le domaine public.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XwfhYHzC9hQWPDnQ2p53GL
This commit is contained in:
Claude committed 2026-06-26 17:25:31 +00:00
1 parent e9f5d4ced5
commit 51f5691f45
4 files changed
+18 -3

No files matched your search

+4 -2
View File
@@ -16,8 +16,10 @@ POSTGRES_DB=pleinr
# persists one automatically. To set it yourself: openssl rand -base64 32
AUTH_SECRET=
# Public URL of the app (used by Auth.js for callbacks).
# With docker-compose the app is published on host port 8413 by default.
AUTH_URL=http://localhost:8413
# Leave EMPTY behind a reverse proxy (Nginx Proxy Manager, Traefik…): Auth.js
# auto-detects it from the Host / X-Forwarded-Proto headers (trustHost).
# Set it only to force a value, e.g. https://pleinr.ffnancy.fr
AUTH_URL=
# ---- First admin user (created by the seed script) ----
SEED_ADMIN_EMAIL=admin@plein-r.fr
+6 -1
View File
@@ -41,7 +41,12 @@ services:
# Optional: if left empty, the container generates and persists one
# automatically (see docker-entrypoint.sh + the app-data volume).
AUTH_SECRET: ${AUTH_SECRET:-}
AUTH_URL: ${AUTH_URL:-http://localhost:8413}
# IMPORTANT behind a reverse proxy: set AUTH_URL to your public URL so the
# login redirect points to the right host, e.g.
# AUTH_URL=https://pleinr.ffnancy.fr
AUTH_URL: ${AUTH_URL:-}
# Lets Auth.js trust the X-Forwarded-* headers from the proxy.
AUTH_TRUST_HOST: "true"
SEED_ON_START: ${SEED_ON_START:-true}
SEED_ADMIN_EMAIL: ${SEED_ADMIN_EMAIL:-admin@plein-r.fr}
SEED_ADMIN_PASSWORD: ${SEED_ADMIN_PASSWORD:-changeme123}
+6
View File
@@ -16,6 +16,12 @@ if [ -z "$AUTH_SECRET" ]; then
export AUTH_SECRET
fi
# If AUTH_URL is empty, unset it so Auth.js derives the public URL from the
# reverse-proxy headers (trustHost) instead of falling back to a hardcoded host.
if [ -z "$AUTH_URL" ]; then
unset AUTH_URL
fi
echo "→ Applying database migrations…"
node dist/migrate.cjs
+2
View File
@@ -2,6 +2,8 @@ import NextAuth from "next-auth";
import { authConfig } from "@/auth.config";
// Edge-safe auth instance (no providers / db) used only to gate routes.
// The redirect target is derived from AUTH_URL (set it to your public URL when
// running behind a reverse proxy, e.g. AUTH_URL=https://pleinr.ffnancy.fr).
export const { auth: middleware } = NextAuth(authConfig);
export default middleware;