Use the X-Forwarded-* headers for keycloak instead of Forwarded

This also explicitly sets X-Forwarded-Proto to https which fixes
the warning "Non-secure context detected; cookies are not secured,
and will not be available in cross-origin POST requests" which
prevented the user account management page to load.
This commit is contained in:
fi 2025-02-11 18:24:45 +01:00
parent c174f625c8
commit e484360f91
2 changed files with 15 additions and 1 deletions

View file

@ -5,7 +5,7 @@
settings = { settings = {
hostname = "https://id.nekover.se"; hostname = "https://id.nekover.se";
hostname-admin = "https://keycloak-admin.nekover.se"; hostname-admin = "https://keycloak-admin.nekover.se";
proxy-headers = "forwarded"; proxy-headers = "xforwarded";
http-enabled = true; http-enabled = true;
http-host = "127.0.0.1"; http-host = "127.0.0.1";
http-port = 8080; http-port = 8080;

View file

@ -41,6 +41,13 @@
proxy_buffer_size 128k; proxy_buffer_size 128k;
proxy_buffers 8 128k; proxy_buffers 8 128k;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Port 443;
# This is https in any case.
proxy_set_header X-Forwarded-Proto https;
# Hide the X-Forwarded header. # Hide the X-Forwarded header.
proxy_hide_header X-Forwarded; proxy_hide_header X-Forwarded;
# Assume we are the only Reverse Proxy (well using Proxy Protocol, but that # Assume we are the only Reverse Proxy (well using Proxy Protocol, but that
@ -96,6 +103,13 @@
proxy_buffer_size 128k; proxy_buffer_size 128k;
proxy_buffers 8 128k; proxy_buffers 8 128k;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Port 443;
# This is https in any case.
proxy_set_header X-Forwarded-Proto https;
# Hide the X-Forwarded header. # Hide the X-Forwarded header.
proxy_hide_header X-Forwarded; proxy_hide_header X-Forwarded;
# Assume we are the only Reverse Proxy (well using Proxy Protocol, but that # Assume we are the only Reverse Proxy (well using Proxy Protocol, but that