guessPotentiallyProxiedOrySdkUrl breaks flows in production behind a non-Vercel reverse proxy
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 45/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- next.js, react, typescript
調査の方向性
@ory/nextjs の guessPotentiallyProxiedOrySdkUrl から始め、getLoginFlow とその他のサーバーサイドの flow 関数が knownProxiedUrl をどのように渡しているかを追跡します。その動作を、middleware の proxyRequest およびクライアントサイドでの @ory/elements-react の使用方法と比較します。Traefik または Vercel 以外のプロキシの背後にある本番デプロイで、開発モードのワークアラウンドなしに、ログイン、登録、リカバリー、検証にプロキシされたアプリ URL が使用されれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
https://busy-mayer-9wpd865lft.projects.oryapis.com
Describe the bug
Hi,
We're integrating Ory Network with a Next.js 16 app using @ory/[email protected] and @ory/[email protected]. Our app runs in Kubernetes behind Traefik Proxy (not Vercel).
The problem: When NODE_ENV=production, all Ory auth flows (login, registration, recovery, verification) break. The browser is redirected to the raw NEXT_PUBLIC_ORY_SDK_URL (our Ory Network custom domain) instead of going through the app's middleware proxy. This results in 404s server-side and CORS errors client-side.
AI root cause findings: guessPotentiallyProxiedOrySdkUrl in @ory/nextjs short-circuits when isProduction() returns true — it returns orySdkUrl() immediately, before ever checking the knownProxiedUrl option. This means the host-header-derived URL (which the flow functions correctly pass as knownProxiedUrl: await getPublicUrl()) is never used in production. The only non-Vercel production path assumes the SDK URL should be used directly, which doesn't work when the app sits behind a reverse proxy that needs to proxy Ory API calls.
Notably, the middleware's proxyRequest function works correctly — it derives selfUrl from request headers. The issue is isolated to the server-side flow functions (getLoginFlow, etc.) and client-side @ory/elements-react components, which both rely on guessPotentiallyProxiedOrySdkUrl.
Current workaround: Setting NEXT_PUBLIC_NODE_ENV=development to trick isProduction() into returning false, which allows the knownProxiedUrl / window.location.origin code paths to execute. This works but is semantically incorrect and fragile.
Our ask: Is there a supported way to run @ory/nextjs in production behind a non-Vercel reverse proxy (e.g. Traefik, Nginx, HAProxy)?
Environment:
@ory/[email protected], @ory/[email protected]
Next.js 16 (standalone output, App Router)
Docker Compose + Traefik Proxy
NEXT_PUBLIC_ORY_SDK_URL points to our Ory Network custom domain
https://github.com/user-attachments/assets/b0dd3ca1-d8e9-41bf-8ff5-29a0a100cb7b
Thanks for any guidance.
Reproducing the bug
See the video attached above
Relevant log output
Relevant configuration
Version
@ory/[email protected] @ory/[email protected]
On which operating system are you observing this issue?
None
In which environment are you deploying?
None
Additional Context
No response
- 主要言語
- TypeScript
- スター
- 187
- フォーク
- 80
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
ory/elements のほかの issue
-
Needs Triage
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
good first issue help wanted upstream
難易度 2/5 1〜3時間 初心者へのやさしさ 45/100
-
good first issue help wanted upstream
難易度 3/5 1〜2日 初心者へのやさしさ 25/100
-
Needs Triage
難易度 3/5 1〜2日 初心者へのやさしさ 52/100
-
Needs Triage
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
似ている issue
-
難易度 1/5 1〜3時間 初心者へのやさしさ 88/100
supabase/agent-skills#611 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 68/100
polka-codes/test#345 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1〜3時間 初心者へのやさしさ 92/100
GoogleChromeLabs/project-sesame#217 ·
メンテナーはふだん 12 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
solana-foundation/solana-com#2202 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100