Set trust proxy so NIP-98 URL matching works behind traefik (X-Forwarded-Proto)
This commit is contained in:
parent
dd90386fb6
commit
395b192432
1 changed files with 7 additions and 0 deletions
|
|
@ -83,6 +83,13 @@ const verifyNip98Auth = async (req: Request): Promise<string | null> => {
|
|||
|
||||
export const server: express.Application = express()
|
||||
|
||||
// Behind a TLS-terminating reverse proxy (traefik in the ansible deploy).
|
||||
// Without this, req.protocol stays "http" and verifyNip98Auth builds an
|
||||
// expectedUrl of http://…, which no browser client will ever sign (clients
|
||||
// sign https://…). Trust one proxy hop so req.protocol honors
|
||||
// X-Forwarded-Proto and NIP-98 URL matching works.
|
||||
server.set('trust proxy', 1)
|
||||
|
||||
// CORS middleware for browser-facing routes only.
|
||||
// The browser hits /subscription with an Authorization header and Content-Type:
|
||||
// application/json, which triggers a CORS preflight. Answer it and allow the
|
||||
|
|
|
|||
Loading…
Reference in a new issue