Skip to content

fix(auth): normalize proxy proto and align oauth backend env config - #133

Merged
LucasSantana-Dev merged 2 commits into
mainfrom
fix/oauth-secure-cookie-proxy-proto
Mar 10, 2026
Merged

LucasSantana-Dev merged 2 commits into
mainfrom
fix/oauth-secure-cookie-proxy-proto

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Mar 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • normalize proxy protocol handling for OAuth/session flows behind reverse proxies
  • add/align backend OAuth-related envs in compose and docs (WEBAPP_BACKEND_URL, CLIENT_SECRET)
  • update .env.example and setup docs to use canonical API callback domain guidance

Why

These changes reduce login/session inconsistencies in proxied production setups and make required env wiring explicit across local and deployed compose environments.

Validation

  • npm run test --workspace=packages/backend -- tests/integration/routes/auth.test.ts --runInBand
  • npm run type:check --workspace=packages/backend

Notes

  • branch was rebased onto current main before final commit
  • no feature behavior changes outside auth/proxy/config wiring

Summary by CodeRabbit

Release Notes

  • New Features

    • Added support for canonicalizing OAuth callbacks to API domain.
    • Introduced new environment variables for improved configuration flexibility.
  • Bug Fixes

    • Enhanced secure session cookie handling in production environments.
    • Improved HTTPS header processing for secure proxy deployments.
    • Added callback alias route for OAuth compatibility.
  • Documentation

    • Updated setup guides and examples to reflect new OAuth callback requirements and environment variable configuration.
  • Tests

    • Added security-focused tests for cookie attributes and OAuth callback flows.

@vercel

vercel Bot commented Mar 10, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment Mar 10, 2026 4:30am

@netlify

netlify Bot commented Mar 10, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for regal-bunny-0c8efe ready!

Name Link
🔨 Latest commit a2cefe7
🔍 Latest deploy log https://app.netlify.com/projects/regal-bunny-0c8efe/deploys/69af9e0bc2365e0008f7827c
😎 Deploy Preview https://deploy-preview-133--regal-bunny-0c8efe.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Mar 10, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

This PR updates OAuth callback routing to use a backend API domain instead of the frontend domain, introduces separate frontend/backend URL configuration variables, and enhances production proxy handling with proper trust settings and header normalization.

Changes

Cohort / File(s) Summary
Environment Configuration
.env.example, docker-compose.dev.yml, docker-compose.yml
Added WEBAPP_FRONTEND_URL, WEBAPP_BACKEND_URL, and CLIENT_SECRET environment variables to support dual frontend/backend URL model with explicit OAuth callback configuration.
Documentation
README.md, CHANGELOG.md, docs/CLOUDFLARE_TUNNEL_SETUP.md, docs/WEBAPP_SETUP.md
Updated setup guides and changelog to reflect OAuth callback routing to backend API domain, canonicalization patterns, and trust proxy settings for production deployments.
Proxy and Session Handling
nginx/nginx.conf, packages/backend/src/server.ts
Configured nginx to normalize X-Forwarded-Proto header with https default; enabled trust proxy in backend production environment for secure session cookies behind reverse proxies.
Test Infrastructure and Integration Tests
packages/backend/tests/setup.ts, packages/backend/tests/integration/routes/auth.test.ts
Enhanced mock session factory with cookie handling logic, HTTPS detection helpers, and secure cookie attribute management; added integration tests validating secure session cookies, canonical callback URLs, and callback alias routing.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

backend, size/m

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title directly and concisely summarizes the main changes: normalizing proxy protocol handling and aligning OAuth backend environment configuration across the codebase.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/oauth-secure-cookie-proxy-proto

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@sonarqubecloud

Copy link
Copy Markdown

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
0.0% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

@LucasSantana-Dev
LucasSantana-Dev merged commit 7887ba7 into main Mar 10, 2026
14 of 16 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the fix/oauth-secure-cookie-proxy-proto branch March 10, 2026 04:33
LucasSantana-Dev added a commit that referenced this pull request May 13, 2026
…133)

* fix(auth): normalize proxy proto for secure oauth sessions

* chore(config): align oauth backend envs in compose and docs

This branch was successfully deployed

1 active deployment
Preview — a2cefe76 Deployed Mar 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant