Skip to content

♻️ refactor(auth): remove NEXT_PUBLIC_AUTH_URL env variable#11658

Merged
tjx666 merged 7 commits intonextfrom
refactor/better-auth-env
Jan 21, 2026
Merged

♻️ refactor(auth): remove NEXT_PUBLIC_AUTH_URL env variable#11658
tjx666 merged 7 commits intonextfrom
refactor/better-auth-env

Conversation

@tjx666
Copy link
Copy Markdown
Member

@tjx666 tjx666 commented Jan 20, 2026

💻 Change Type

  • ✨ feat
  • 🐛 fix
  • ♻️ refactor
  • 💄 style
  • 👷 build
  • ⚡️ perf
  • ✅ test
  • 📝 docs
  • 🔨 chore

🔗 Related Issue

Related to https://linear.app/lobehub/issue/LOBE-3914

🔀 Description of Change

Simplify user configuration by removing the NEXT_PUBLIC_AUTH_URL environment variable:

Client-side:

  • Rely on Better Auth's default behavior (uses current page origin automatically)
  • Remove baseURL configuration from auth-client.ts

Server-side:

  • Use APP_URL directly for:
    • Better Auth baseURL configuration
    • Passkey rpID and origins
    • SSO provider redirectURI
    • Login redirect URLs in middleware (supports CDN/proxy scenarios)

Files changed:

  • src/envs/auth.ts - Remove schema, runtimeEnv, resolvePublicAuthUrl() function
  • src/libs/better-auth/auth-client.ts - Remove baseURL config
  • src/libs/better-auth/define-config.ts - Use process.env.APP_URL for passkey and baseURL
  • src/libs/better-auth/sso/index.ts - Use process.env.APP_URL for redirectURI
  • src/libs/better-auth/utils/config.ts - Remove from trusted origins defaults
  • src/libs/next/proxy/define-config.ts - Use process.env.APP_URL for login redirects
  • scripts/prebuild.mts - Remove log output, add Vercel URL env vars
  • Config files: .env.example, .env.example.development, Dockerfile
  • Docs: docs/self-hosting/environment-variables/auth.mdx, etc.

🧪 How to Test

  • Tested locally
  • Added/updated tests
  • No tests needed
  1. Run bunx vitest run 'src/envs/auth.test.ts' - should pass
  2. Verify no TypeScript errors in modified files

📸 Screenshots / Videos

N/A - No UI changes

📝 Additional Information

Breaking change: Users who previously set NEXT_PUBLIC_AUTH_URL should remove it from their configuration. The system now uses APP_URL on the server side and the browser's current origin on the client side.

@vercel
Copy link
Copy Markdown

vercel bot commented Jan 20, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
lobehub Ready Ready Preview, Comment Jan 21, 2026 3:49am

Request Review

Copy link
Copy Markdown
Contributor

@sourcery-ai sourcery-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @tjx666, you have reached your weekly rate limit of 500000 diff characters.

Please try again later or upgrade to continue using Sourcery

@dosubot dosubot bot added the size:L This PR changes 100-499 lines, ignoring generated files. label Jan 20, 2026
@gru-agent
Copy link
Copy Markdown
Contributor

gru-agent bot commented Jan 20, 2026

TestGru Assignment

Summary

Link CommitId Status Reason
Detail 7c0fdb1feac2a8abda871cd752585d40ac8e3ade 🚫 Skipped No files need to be tested {".env.example":"File path does not match include patterns.",".env.example.development":"File path does not match include patterns.","Dockerfile":"File path does not match include patterns.","docs/self-hosting/advanced/auth.mdx":"File path does not match include patterns.","docs/self-hosting/advanced/auth.zh-CN.mdx":"File path does not match include patterns.","docs/self-hosting/environment-variables/auth.mdx":"File path does not match include patterns.","docs/self-hosting/environment-variables/auth.zh-CN.mdx":"File path does not match include patterns.","scripts/prebuild.mts":"File path does not match include patterns.","src/envs/auth.test.ts":"File path does not match include patterns.","src/envs/auth.ts":"File path does not match include patterns.","src/libs/better-auth/auth-client.ts":"File path does not match include patterns.","src/libs/better-auth/define-config.ts":"File path does not match include patterns.","src/libs/better-auth/sso/index.ts":"File p…

History Assignment

Tip

You can @gru-agent and leave your feedback. TestGru will make adjustments based on your input

@dosubot dosubot bot added the 📝 Documentation Improvements or additions to documentation label Jan 20, 2026
Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7c0fdb1fea

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment on lines 239 to 243
logNextAuth('Request a protected route, redirecting to sign-in page');
const authUrl = authEnv.NEXT_PUBLIC_AUTH_URL;
const callbackUrl = `${authUrl}${req.nextUrl.pathname}${req.nextUrl.search}`;
const nextLoginUrl = new URL('/next-auth/signin', authUrl);
const appUrl = process.env.APP_URL;
const callbackUrl = `${appUrl}${req.nextUrl.pathname}${req.nextUrl.search}`;
const nextLoginUrl = new URL('/next-auth/signin', appUrl);
nextLoginUrl.searchParams.set('callbackUrl', callbackUrl);
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Guard redirect URLs when APP_URL is unset

This now uses process.env.APP_URL directly to build callbackUrl and new URL('/next-auth/signin', appUrl). In Vercel deployments where APP_URL is not set (the project previously relied on the fallback from VERCEL_URL in getAppConfig()), appUrl is undefined, which will throw in new URL(...) and will also produce callback URLs prefixed with undefined, breaking auth redirects for protected routes. Consider using the resolved app URL (e.g., appEnv.APP_URL) or restoring the previous fallback logic.

Useful? React with 👍 / 👎.

@codecov
Copy link
Copy Markdown

codecov bot commented Jan 20, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 74.08%. Comparing base (a8b042f) to head (8a4e6d0).
⚠️ Report is 4 commits behind head on next.

Additional details and impacted files
@@            Coverage Diff            @@
##             next   #11658     +/-   ##
=========================================
  Coverage   74.07%   74.08%             
=========================================
  Files        1187     1187             
  Lines       94491    94473     -18     
  Branches    12860    10823   -2037     
=========================================
- Hits        69997    69993      -4     
+ Misses      24404    24390     -14     
  Partials       90       90             
Flag Coverage Δ
app 66.93% <100.00%> (+0.01%) ⬆️
database 93.29% <ø> (ø)
packages/agent-runtime 90.20% <ø> (ø)
packages/context-engine 85.29% <ø> (ø)
packages/conversation-flow 92.37% <ø> (ø)
packages/file-loaders 88.66% <ø> (ø)
packages/memory-user-memory 69.75% <ø> (ø)
packages/model-bank 100.00% <ø> (ø)
packages/model-runtime 86.70% <ø> (ø)
packages/prompts 79.33% <ø> (ø)
packages/python-interpreter 92.90% <ø> (ø)
packages/ssrf-safe-fetch 0.00% <ø> (ø)
packages/utils 93.25% <ø> (ø)
packages/web-crawler 95.62% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

Components Coverage Δ
Store 66.91% <ø> (ø)
Services 50.81% <ø> (ø)
Server 67.82% <100.00%> (+<0.01%) ⬆️
Libs 41.13% <ø> (ø)
Utils 93.82% <ø> (ø)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

- Client: rely on Better Auth default behavior (uses current page origin)
- Server: use APP_URL directly for baseURL, passkey config, and SSO redirect
- Middleware: use APP_URL for login redirects (supports CDN/proxy scenarios)
- Remove resolvePublicAuthUrl() fallback function
- Update docs, configs, and tests accordingly
Add VERCEL_BRANCH_URL and VERCEL_PROJECT_PRODUCTION_URL to prebuild log
Replace direct process.env.APP_URL access with appEnv.APP_URL for
consistent environment variable handling across the codebase.
Use more stable URLs for Vercel deployments:
- Production: VERCEL_PROJECT_PRODUCTION_URL (project level)
- Preview: VERCEL_BRANCH_URL (branch level, stable across deployments)
- Fallback: VERCEL_URL (deployment level, least stable)

This provides more consistent URLs for OAuth callbacks and other
scenarios requiring stable URLs.
- Add @vitest-environment node to run in server context
- Update expected port from 3010 to 3210 (non-dev default)
@tjx666 tjx666 force-pushed the refactor/better-auth-env branch from 1c68af4 to 2ac83e1 Compare January 21, 2026 03:07
Cover Vercel URL fallback order:
- VERCEL_PROJECT_PRODUCTION_URL for production
- VERCEL_BRANCH_URL for preview
- VERCEL_URL as final fallback

Cover local environment:
- localhost:3010 for development
- localhost:3210 for non-development
@tjx666 tjx666 merged commit c0f9875 into next Jan 21, 2026
35 of 36 checks passed
@tjx666 tjx666 deleted the refactor/better-auth-env branch January 21, 2026 03:51
@lobehubbot
Copy link
Copy Markdown
Member

❤️ Great PR @tjx666 ❤️

The growth of project is inseparable from user feedback and contribution, thanks for your contribution! If you are interesting with the lobehub developer community, please join our discord and then dm @arvinxx or @canisminor1990. They will invite you to our private developer channel. We are talking about the lobe-chat development or sharing ai newsletter around the world.

lobehubbot pushed a commit that referenced this pull request Jan 21, 2026
## [Version&nbsp;2.0.0-next.329](v2.0.0-next.328...v2.0.0-next.329)
<sup>Released on **2026-01-21**</sup>

#### ♻ Code Refactoring

- **auth**: Remove NEXT_PUBLIC_AUTH_URL env variable.

#### 🐛 Bug Fixes

- **misc**: Sloved the old removeSessionTopics not work.

<br/>

<details>
<summary><kbd>Improvements and Fixes</kbd></summary>

#### Code refactoring

* **auth**: Remove NEXT_PUBLIC_AUTH_URL env variable, closes [#11658](#11658) ([c0f9875](c0f9875))

#### What's fixed

* **misc**: Sloved the old removeSessionTopics not work, closes [#11671](#11671) ([06d41e5](06d41e5))

</details>

<div align="right">

[![](https://img.shields.io/badge/-BACK_TO_TOP-151515?style=flat-square)](#readme-top)

</div>
@lobehubbot
Copy link
Copy Markdown
Member

🎉 This PR is included in version 2.0.0-next.329 🎉

The release is available on:

Your semantic-release bot 📦🚀

JamieStivala pushed a commit to jaworldwideorg/OneJA-Bot that referenced this pull request Jan 23, 2026
## [Version&nbsp;1.153.0](v1.152.0...v1.153.0)
<sup>Released on **2026-01-23**</sup>

#### ♻ Code Refactoring

- **auth**: Remove NEXT_PUBLIC_AUTH_URL env variable.
- **model-select**: Migrate FunctionCallingModelSelect to LobeSelect.
- **ModelSwitchPanel**: Migrate from Popover to DropdownMenu with virtual scrolling.
- **userMemories**: Removed un-used code.
- **misc**: Improve memory data with experience and identity, move vercel-react-best-practices skills to .agents directory.

#### ✨ Features

- **database**: Added user memory activity.
- **desktop**: Add legacy local database detection and migration guidance.
- **misc**: Add platform-aware download client menu option, add server version check for desktop app, remove Clerk authentication code, skill setting page and skill store, support agent group unpublish agents, support client tasks mode, update the sandbox preinstall libs in sys role.

#### 🐛 Bug Fixes

- **copilot**: Pass correct scope when creating new session in PageEditor.
- **desktop**: Gracefully handle missing update manifest 404 errors.
- **model-runtime**: Filter unsupported image types (SVG) before sending to vision models.
- **pdf**: Upgrade pdfjs-dist and react-pdf to v5.x.
- **sidebar-drawer**: Fix drawer positioning and title style.
- **misc**: Fix group broadcast trigger tool use, fix local system tools, fix memory schema, fix multi agent tasks issue, fix multi tasks no summary issue, fix scope issue, fix tool argument scape and improve multi task run, fixed the sandbox tools call when error should use right callback, improve e2e server and complete i18n resources, slove the agent group editor not focus in editdata area, slove the agents header switch agents the lobeAI not show problem, sloved the old removeSessionTopics not work, TypewriterEffect not refreshing on language change, updata cron job ui & fixed commnuity pagenation goto error, update the agentbuilder tools not always use humanIntervention.

#### 💄 Styles

- **misc**: Improve auto scroll and group profile, update og, update share style.

<br/>

<details>
<summary><kbd>Improvements and Fixes</kbd></summary>

#### Code refactoring

* **auth**: Remove NEXT_PUBLIC_AUTH_URL env variable, closes [lobehub#11658](https://github.com/jaworldwideorg/OneJA-Bot/issues/11658) ([c0f9875](c0f9875))
* **model-select**: Migrate FunctionCallingModelSelect to LobeSelect, closes [lobehub#11664](https://github.com/jaworldwideorg/OneJA-Bot/issues/11664) ([ad51305](ad51305))
* **ModelSwitchPanel**: Migrate from Popover to DropdownMenu with virtual scrolling, closes [lobehub#11663](https://github.com/jaworldwideorg/OneJA-Bot/issues/11663) ([c9d9dff](c9d9dff))
* **userMemories**: Removed un-used code, closes [lobehub#11713](https://github.com/jaworldwideorg/OneJA-Bot/issues/11713) ([89750fc](89750fc))
* **misc**: Improve memory data with experience and identity, closes [lobehub#11717](https://github.com/jaworldwideorg/OneJA-Bot/issues/11717) ([bdb3eb4](bdb3eb4))
* **misc**: Move vercel-react-best-practices skills to .agents directory, closes [lobehub#11703](https://github.com/jaworldwideorg/OneJA-Bot/issues/11703) ([6df7731](6df7731))

#### What's improved

* **database**: Added user memory activity, closes [lobehub#11680](https://github.com/jaworldwideorg/OneJA-Bot/issues/11680) ([0160fbd](0160fbd))
* **desktop**: Add legacy local database detection and migration guidance, closes [lobehub#11682](https://github.com/jaworldwideorg/OneJA-Bot/issues/11682) ([5664b84](5664b84))
* **misc**: Add platform-aware download client menu option, closes [lobehub#11676](https://github.com/jaworldwideorg/OneJA-Bot/issues/11676) ([55abddc](55abddc))
* **misc**: Add server version check for desktop app, closes [lobehub#11710](https://github.com/jaworldwideorg/OneJA-Bot/issues/11710) ([0cf2723](0cf2723))
* **misc**: Remove Clerk authentication code, closes [lobehub#11711](https://github.com/jaworldwideorg/OneJA-Bot/issues/11711) ([395595a](395595a))
* **misc**: Skill setting page and skill store, closes [lobehub#11665](https://github.com/jaworldwideorg/OneJA-Bot/issues/11665) ([d8c0c26](d8c0c26))
* **misc**: Support agent group unpublish agents, closes [lobehub#11687](https://github.com/jaworldwideorg/OneJA-Bot/issues/11687) ([4e060be](4e060be))
* **misc**: Support client tasks mode, closes [lobehub#11666](https://github.com/jaworldwideorg/OneJA-Bot/issues/11666) ([98cf57b](98cf57b))
* **misc**: Update the sandbox preinstall libs in sys role, closes [lobehub#11688](https://github.com/jaworldwideorg/OneJA-Bot/issues/11688) ([404c577](404c577))

#### What's fixed

* **copilot**: Pass correct scope when creating new session in PageEditor, closes [lobehub#11714](https://github.com/jaworldwideorg/OneJA-Bot/issues/11714) ([0259270](0259270))
* **desktop**: Gracefully handle missing update manifest 404 errors, closes [lobehub#11625](https://github.com/jaworldwideorg/OneJA-Bot/issues/11625) ([13e95b9](13e95b9))
* **model-runtime**: Filter unsupported image types (SVG) before sending to vision models, closes [lobehub#11698](https://github.com/jaworldwideorg/OneJA-Bot/issues/11698) ([c0c99a7](c0c99a7))
* **pdf**: Upgrade pdfjs-dist and react-pdf to v5.x, closes [lobehub#11686](https://github.com/jaworldwideorg/OneJA-Bot/issues/11686) ([2b620df](2b620df))
* **sidebar-drawer**: Fix drawer positioning and title style, closes [lobehub#11655](https://github.com/jaworldwideorg/OneJA-Bot/issues/11655) ([cf5320e](cf5320e))
* **misc**: Fix group broadcast trigger tool use, closes [lobehub#11646](https://github.com/jaworldwideorg/OneJA-Bot/issues/11646) ([831a9b3](831a9b3))
* **misc**: Fix local system tools, closes [lobehub#11702](https://github.com/jaworldwideorg/OneJA-Bot/issues/11702) ([6548fc7](6548fc7))
* **misc**: Fix memory schema, closes [lobehub#11645](https://github.com/jaworldwideorg/OneJA-Bot/issues/11645) ([3baf780](3baf780))
* **misc**: Fix multi agent tasks issue, closes [lobehub#11672](https://github.com/jaworldwideorg/OneJA-Bot/issues/11672) ([9de773b](9de773b))
* **misc**: Fix multi tasks no summary issue, closes [lobehub#11685](https://github.com/jaworldwideorg/OneJA-Bot/issues/11685) ([26ce317](26ce317))
* **misc**: Fix scope issue, closes [lobehub#11719](https://github.com/jaworldwideorg/OneJA-Bot/issues/11719) ([17adde8](17adde8))
* **misc**: Fix tool argument scape and improve multi task run, closes [lobehub#11691](https://github.com/jaworldwideorg/OneJA-Bot/issues/11691) ([b13bb8a](b13bb8a))
* **misc**: Fixed the sandbox tools call when error should use right callback, closes [lobehub#11721](https://github.com/jaworldwideorg/OneJA-Bot/issues/11721) ([e8fce68](e8fce68))
* **misc**: Improve e2e server and complete i18n resources, closes [lobehub#11678](https://github.com/jaworldwideorg/OneJA-Bot/issues/11678) ([d450dd9](d450dd9))
* **misc**: Slove the agent group editor not focus in editdata area, closes [lobehub#11677](https://github.com/jaworldwideorg/OneJA-Bot/issues/11677) ([9ac84e6](9ac84e6))
* **misc**: Slove the agents header switch agents the lobeAI not show problem, closes [lobehub#11726](https://github.com/jaworldwideorg/OneJA-Bot/issues/11726) ([f45f508](f45f508))
* **misc**: Sloved the old removeSessionTopics not work, closes [lobehub#11671](https://github.com/jaworldwideorg/OneJA-Bot/issues/11671) ([06d41e5](06d41e5))
* **misc**: TypewriterEffect not refreshing on language change, closes [lobehub#11657](https://github.com/jaworldwideorg/OneJA-Bot/issues/11657) ([ba30f46](ba30f46))
* **misc**: Updata cron job ui & fixed commnuity pagenation goto error, closes [lobehub#11700](https://github.com/jaworldwideorg/OneJA-Bot/issues/11700) ([42ad2a0](42ad2a0))
* **misc**: Update the agentbuilder tools not always use humanIntervention, closes [lobehub#11696](https://github.com/jaworldwideorg/OneJA-Bot/issues/11696) ([0d3017b](0d3017b))

#### Styles

* **misc**: Improve auto scroll and group profile, closes [lobehub#11725](https://github.com/jaworldwideorg/OneJA-Bot/issues/11725) ([550acc2](550acc2))
* **misc**: Update og, closes [lobehub#11709](https://github.com/jaworldwideorg/OneJA-Bot/issues/11709) ([01cf4e4](01cf4e4))
* **misc**: Update share style, closes [lobehub#11716](https://github.com/jaworldwideorg/OneJA-Bot/issues/11716) ([3c70dfa](3c70dfa))

</details>

<div align="right">

[![](https://img.shields.io/badge/-BACK_TO_TOP-151515?style=flat-square)](#readme-top)

</div>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

📝 Documentation Improvements or additions to documentation released on @next size:L This PR changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants