-
Notifications
You must be signed in to change notification settings - Fork 177
Open
Labels
enhancementNew feature or requestNew feature or requestquestionFurther information is requestedFurther information is requested
Description
ref/discussion: see #752
When OpenNext is behind a reverse proxy (i.e. aws wrappers) the host can be retrieved from header["x-forwarded-host"].
For Node, it depends how the infra is setup (behind a RP or not).
We also have this:
opennextjs-aws/packages/open-next/src/core/requestHandler.ts
Lines 46 to 48 in e48951f
| if (initialHeaders["x-forwarded-host"]) { | |
| initialHeaders.host = initialHeaders["x-forwarded-host"]; | |
| } |
header["x-forwarded-host"] should not be trusted if not behind a reverse proxy as it can be forged.
We should figure out the best way to configure this.
khuezy
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestquestionFurther information is requestedFurther information is requested