Update X-Forwarded-Proto directive in backend.conf#1586
Merged
alxndrsn merged 1 commit intogetodk:nextfrom Dec 29, 2025
Merged
Conversation
Updates the nginx odk setup script to point to the correct nginx configuration file when pinning `X-Forwarded-Proto` to 'https'. Fixes a minor regression introduced during refactoring in 924d320. For more discussion, see https://forum.getodk.org/t/setting-up-central-behind-a-proxy-this-authentication-method-is-only-available-over-https/57236/10.
Contributor
|
Thanks for the fix!
I'd say it's quite a big regression for anyone using |
alxndrsn
approved these changes
Dec 29, 2025
Contributor
alxndrsn
left a comment
There was a problem hiding this comment.
Tested locally, and looks good.
I'll follow up with relevant tests.
This was referenced Dec 29, 2025
Contributor
Contributor
Author
|
Thanks @alxndrsn ! Fixes look good to me and I appreciate all your work on this. |
alxndrsn
added a commit
that referenced
this pull request
Dec 30, 2025
Adapt existing nginx tests to run with both: 1. `SSL_TYPE=selfsign` (as happened previously), and 2. `SSL_TYPE=upstream` (previously untested, as exposed in #1586)
drguptavivek
added a commit
to drguptavivek/central
that referenced
this pull request
Jan 12, 2026
- Detailed file-by-file conflict analysis - VG login hardening vs upstream error handling - Resolution strategy: Layer VG on top (Option A) - Testing checklist and rollback plan Issue: central-xav.3
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR fixes a regression in behavior reported on the ODK forum here. The regression was introduced in 924d320 during a code refactor. The code refactor moved the
X-Forwarded-Protoheader to a new file but did not update the regexp which pins this header tohttpsinsetup-odk.shscript to point to that file. The result is that HTTP authentication breaks for users hosting ODK behind a reverse proxy.What has been done to verify that this works as intended?
I have made the changes on my local installation, rerun the docker compose build, and confirmed that the issues reported in this forum post are resolved. I can log into my server without throwing the
httpsOnly()error.Why is this the best possible solution? Were any other approaches considered?
I believe this is a minor regression introduced during code refactoring in error. This emulates the behavior of the build script before 924d320.
How does this change affect users? Describe intentional changes to behavior and behavior that could have accidentally been affected by code changes. In other words, what are the regression risks?
This fixes a regression in behavior, and should not introduce more breakages.
Does this change require updates to documentation? If so, please file an issue here and include the link below.
No.
Before submitting this PR, please make sure you have:
nextbranch OR only changed documentation/infrastructure (masteris stable and used in production)