Skip to content

fix(self-hosted): allow larger OAuth response headers in Docker guide - #585

Open
chimit wants to merge 3 commits into
chatwoot:mainfrom
chimit:fix/nginx-oauth-response-headers
Open

chimit wants to merge 3 commits into
chatwoot:mainfrom
chimit:fix/nginx-oauth-response-headers

Conversation

@chimit

@chimit chimit commented Sep 30, 2026 •

Copy link
Copy Markdown

The Docker deployment guide now includes Nginx buffer settings that allow larger OAuth response headers. This prevents a 502 on the Google sign-in callback when Nginx reports upstream sent too big header while reading response header from upstream.

How to reproduce

Deploy Chatwoot with Docker Compose and the guide's Nginx example, configure Google sign-in, and follow /omniauth/google_oauth2/callback with a response header block larger than Nginx's default 4–8 KiB proxy buffer.

What changed

Increase proxy_buffer_size to 32 KiB and set proxy_buffers high enough to satisfy Nginx's buffer-size checks, including on systems with 4 KiB memory pages. The configuration was syntax-checked with proxy_buffering off, as shown in the guide.

Related Nginx sample config PR: chatwoot/chatwoot#16083

Copilot AI balanced review requested due to automatic review settings September 30, 2026 05:04

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Two of the three added directives (proxy_buffers and proxy_busy_buffers_size) have no effect while proxy_buffering off; is set, so the documented config is potentially misleading about what fixes the issue.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

This PR updates the self-hosted Docker deployment guide (self-hosted/deployment/docker.mdx) to add Nginx proxy buffer settings inside the reverse-proxy location / block. The goal is to prevent a 502 error on the Google sign-in callback caused by Nginx reporting upstream sent too big header while reading response header from upstream, which happens when OAuth response headers (e.g., large session cookies) exceed the default 4–8 KiB proxy buffer.

Changes:

  • Adds proxy_buffer_size 32k; to allow reading larger OAuth response headers.
  • Adds proxy_buffers 8 16k; and proxy_busy_buffers_size 32k; as compatible companion values.
  • Adds an explanatory comment describing the intent of the buffer settings.
File Description
self-hosted/​deployment/​docker.mdx Adds Nginx proxy buffer directives to the documented reverse-proxy config to avoid a 502 on the OAuth callback from oversized response headers.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread self-hosted/deployment/docker.mdx Outdated

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants