Set trust proxy so NIP-98 URL matching works behind traefik (X-Forwarded-Proto)
All checks were successful
CI / checks (push) Successful in 43s

This commit is contained in:
hudson 2026-09-16 15:15:26 -04:00 committed by Agent
parent c21ed9f71d
commit 8235513822

View file

@ -83,6 +83,13 @@ const verifyNip98Auth = async (req: Request): Promise<string | null> => {
export const server: express.Application = express() export const server: express.Application = express()
// Behind a TLS-terminating reverse proxy (traefik in the ansible deploy).
// Without this, req.protocol stays "http" and verifyNip98Auth builds an
// expectedUrl of http://…, which no browser client will ever sign (clients
// sign https://…). Trust one proxy hop so req.protocol honors
// X-Forwarded-Proto and NIP-98 URL matching works.
server.set('trust proxy', 1)
// CORS middleware for browser-facing routes only. // CORS middleware for browser-facing routes only.
// The browser hits /subscription with an Authorization header and Content-Type: // The browser hits /subscription with an Authorization header and Content-Type:
// application/json, which triggers a CORS preflight. Answer it and allow the // application/json, which triggers a CORS preflight. Answer it and allow the