guessPotentiallyProxiedOrySdkUrl breaks flows in production behind a non-Vercel reverse proxy
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 45/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- next.js, react, typescript
- Lĩnh vực
- authentication, backend-api-design, networking
Hướng nghiên cứu
Bắt đầu với guessPotentiallyProxiedOrySdkUrl trong @ory/nextjs, sau đó theo dõi cách getLoginFlow và các hàm flow phía server khác truyền knownProxiedUrl. So sánh hành vi đó với proxyRequest của middleware và cách sử dụng @ory/elements-react phía client. Được coi là hoàn tất khi các deployment production phía sau Traefik hoặc một proxy khác không phải Vercel sử dụng URL của app được proxy cho đăng nhập, đăng ký, khôi phục và xác minh mà không cần workaround của chế độ development.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
https://busy-mayer-9wpd865lft.projects.oryapis.com
Describe the bug
Hi,
We're integrating Ory Network with a Next.js 16 app using @ory/[email protected] and @ory/[email protected]. Our app runs in Kubernetes behind Traefik Proxy (not Vercel).
The problem: When NODE_ENV=production, all Ory auth flows (login, registration, recovery, verification) break. The browser is redirected to the raw NEXT_PUBLIC_ORY_SDK_URL (our Ory Network custom domain) instead of going through the app's middleware proxy. This results in 404s server-side and CORS errors client-side.
AI root cause findings: guessPotentiallyProxiedOrySdkUrl in @ory/nextjs short-circuits when isProduction() returns true — it returns orySdkUrl() immediately, before ever checking the knownProxiedUrl option. This means the host-header-derived URL (which the flow functions correctly pass as knownProxiedUrl: await getPublicUrl()) is never used in production. The only non-Vercel production path assumes the SDK URL should be used directly, which doesn't work when the app sits behind a reverse proxy that needs to proxy Ory API calls.
Notably, the middleware's proxyRequest function works correctly — it derives selfUrl from request headers. The issue is isolated to the server-side flow functions (getLoginFlow, etc.) and client-side @ory/elements-react components, which both rely on guessPotentiallyProxiedOrySdkUrl.
Current workaround: Setting NEXT_PUBLIC_NODE_ENV=development to trick isProduction() into returning false, which allows the knownProxiedUrl / window.location.origin code paths to execute. This works but is semantically incorrect and fragile.
Our ask: Is there a supported way to run @ory/nextjs in production behind a non-Vercel reverse proxy (e.g. Traefik, Nginx, HAProxy)?
Environment:
@ory/[email protected], @ory/[email protected]
Next.js 16 (standalone output, App Router)
Docker Compose + Traefik Proxy
NEXT_PUBLIC_ORY_SDK_URL points to our Ory Network custom domain
https://github.com/user-attachments/assets/b0dd3ca1-d8e9-41bf-8ff5-29a0a100cb7b
Thanks for any guidance.
Reproducing the bug
See the video attached above
Relevant log output
Relevant configuration
Version
@ory/[email protected] @ory/[email protected]
On which operating system are you observing this issue?
None
In which environment are you deploying?
None
Additional Context
No response
- Ngôn ngữ chính
- TypeScript
- Star
- 187
- Fork
- 80
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của ory/elements
-
Needs Triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
good first issue help wanted upstream
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 45/100
-
good first issue help wanted upstream
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 25/100
-
Add React-only examplesĐang mởNeeds Triage
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 52/100
-
Needs Triage
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
Issue tương tự
-
needs:triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
ai-discovered
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 83/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
jessepollak/home#1627 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent-canvas bug llm priority:low ready-for-dev
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
OpenHands/OpenHands#17806 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
radius-project/ai-extensions#923 ·
Maintainer thường phản hồi trong vòng 1 ngày