Merge pull request #243 from trails-cool/fix/overpass-proxy-forwarded-origin

Fix /api/overpass 403 behind Caddy reverse proxy
This commit is contained in:
Ullrich Schäfer 2026-04-18 02:25:28 +02:00 committed by GitHub
commit 6bba7e31a7
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -50,9 +50,16 @@ export async function action({ request }: Route.ActionArgs) {
return new Response("Method not allowed", { status: 405 });
}
// Same-origin check. Trust Caddy's X-Forwarded-* headers when present so
// the check works behind the reverse proxy (request.url inside the container
// is http://planner:3001/..., but the browser Origin is https://planner.trails.cool).
const origin = request.headers.get("origin");
const requestUrl = new URL(request.url);
const expectedOrigin = `${requestUrl.protocol}//${requestUrl.host}`;
const forwardedHost = request.headers.get("x-forwarded-host");
const forwardedProto = request.headers.get("x-forwarded-proto");
const host = forwardedHost ?? requestUrl.host;
const proto = forwardedProto ?? requestUrl.protocol.replace(":", "");
const expectedOrigin = `${proto}://${host}`;
if (!origin || origin !== expectedOrigin) {
return new Response("Forbidden", { status: 403 });
}