Skip to content

fix: require AUTH_URL in production - #49

Merged
voidash merged 1 commit into
mainfrom
fix/require-auth-url
Oct 3, 2026
Merged

voidash merged 1 commit into
mainfrom
fix/require-auth-url

Conversation

@voidash

@voidash voidash commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator

What changed

The production server now requires AUTH_URL, the public origin of the site. Without it, the GitHub OAuth callback URL was built from the container's bind address (http://0.0.0.0:3000/...), so sign-in failed behind any proxy. Forwarded host headers did not change that.

  • apps/api/src/config.ts: AUTH_URL is validated, and required when NODE_ENV is production. Validation moves into a pure parseEnv() so it can be tested; getEnv() still caches the result.
  • apps/api/.env.example: AUTH_URL=http://localhost:3000, with a comment.
  • docs/deployment.md: the OAuth step names AUTH_URL, and there is a known-problems row for the callback mismatch.

Closes #48

Contract impact

  • No changes to packages/api-contract

Checks

  • bun run lint
  • bun run typecheck
  • bun run test (153 passed, including 3 new tests; the production test fails if the rule is removed)
  • bun run build

Checked against a production container, reading the callback URL from /api/auth/providers:

Setup Callback URL
No AUTH_URL, any Host header http://0.0.0.0:3000/api/auth/callback/github
No AUTH_URL, with X-Forwarded-Host and X-Forwarded-Proto: https https://0.0.0.0:3000/... (host still wrong)
AUTH_URL=https://devnepal.gov.np https://devnepal.gov.np/api/auth/callback/github
Same, with a spoofed X-Forwarded-Host unchanged, still the AUTH_URL origin

Notes for reviewers

Any existing deployment must set AUTH_URL before running this version: the app now refuses to start without it, instead of starting with broken sign-in.

Foundation checklist

  • Commits signed off (git commit -s)
  • Works in both English and Nepali where applicable (no text changes)
  • No secrets or real personal data anywhere in the diff
  • Documentation updated

Without AUTH_URL, the production server built the GitHub callback URL
from its own bind address (http://0.0.0.0:3000), and forwarded host
headers did not change it, so sign-in failed behind a proxy. AUTH_URL
is now validated and required when NODE_ENV is production, and it is
documented in .env.example and the deployment checklist.

Signed-off-by: voidash <ashish.thapa477@gmail.com>
@voidash
voidash merged commit 88528c8 into main Oct 3, 2026
1 check passed
@voidash
voidash deleted the fix/require-auth-url branch October 3, 2026 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GitHub sign-in callback uses the container address unless AUTH_URL is set

2 participants