fix: use public origins for SSO redirects

This commit is contained in:
2026-07-20 15:04:20 +05:30
parent a75779fa4d
commit 944f83d3f4
57 changed files with 138 additions and 89 deletions
+8 -4
View File
@@ -166,10 +166,13 @@ export function forwardAuthFailure(res: Response, verifierUrl: string): Response
}
/** Describe the original gateway request to a forward-auth verifier. */
export function forwardAuthHeaders(req: Request): Headers {
export function forwardAuthHeaders(req: Request, publicOrigin?: string): Headers {
const original = new URL(req.url);
const host = req.headers.get("host") ?? original.host;
const protocol = original.protocol.replace(":", "");
const protocol = (publicOrigin ? new URL(publicOrigin).protocol : original.protocol).replace(
":",
"",
);
return new Headers({
cookie: req.headers.get("cookie") ?? "",
authorization: req.headers.get("authorization") ?? "",
@@ -194,6 +197,7 @@ async function checkAuth(
req: Request,
ip: string,
internalOrigins: Readonly<Record<string, string>>,
publicOrigin?: string,
): Promise<Response | null> {
if (!auth) return null;
@@ -225,7 +229,7 @@ async function checkAuth(
try {
const res = await fetch(verifyUrl, {
headers: forwardAuthHeaders(req),
headers: forwardAuthHeaders(req, publicOrigin),
redirect: "manual",
});
if (!res.ok) {
@@ -492,7 +496,7 @@ export async function startGateway(opts: GatewayOptions): Promise<RunningGateway
}
// Per-app access control (basic auth / IP allowlist / forward-auth).
const denied = await checkAuth(target.auth, req, ip, internalOrigins);
const denied = await checkAuth(target.auth, req, ip, internalOrigins, target.publicOrigin);
if (denied) {
if (sec.accessLog)
console.log(