Update Nginx configuration to use $is_request_port and $request_port for improved compatibility

Signed-off-by: Eric Nemchik <eric@nemchik.com>
This commit is contained in:
Eric Nemchik
2026-07-18 13:42:25 -05:00
parent a393925f44
commit a2509cc44e
4 changed files with 8 additions and 8 deletions
@@ -28,7 +28,7 @@ location @authelia_proxy_signin {
add_header Set-Cookie $set_cookie; add_header Set-Cookie $set_cookie;
## Set the $target_url variable based on the original request ## Set the $target_url variable based on the original request
set_escape_uri $target_url $scheme://$host:$server_port$request_uri; set_escape_uri $target_url $scheme://$host$is_request_port$request_port$request_uri;
## Translate the Location response header from the auth subrequest into a variable ## Translate the Location response header from the auth subrequest into a variable
auth_request_set $signin_url $upstream_http_location; auth_request_set $signin_url $upstream_http_location;
@@ -38,10 +38,10 @@ location @goauthentik_proxy_signin {
add_header Set-Cookie $set_cookie; add_header Set-Cookie $set_cookie;
## Set the $target_url variable based on the original request ## Set the $target_url variable based on the original request
set_escape_uri $target_url $scheme://$host:$server_port$request_uri; set_escape_uri $target_url $scheme://$host$is_request_port$request_port$request_uri;
## Set the $signin_url variable ## Set the $signin_url variable
set $signin_url https://$host:$server_port/outpost.goauthentik.io/start?rd=$target_url; set $signin_url https://$host$is_request_port$request_port/outpost.goauthentik.io/start?rd=$target_url;
## Redirect to login ## Redirect to login
return 302 $signin_url; return 302 $signin_url;
+3 -3
View File
@@ -21,11 +21,11 @@ proxy_no_cache $cookie_session;
# Proxy Header Settings # Proxy Header Settings
proxy_set_header Connection $connection_upgrade; proxy_set_header Connection $connection_upgrade;
proxy_set_header Early-Data $ssl_early_data; proxy_set_header Early-Data $ssl_early_data;
proxy_set_header Host $host; proxy_set_header Host $host$is_request_port$request_port;
proxy_set_header Proxy ""; proxy_set_header Proxy "";
proxy_set_header Upgrade $http_upgrade; proxy_set_header Upgrade $http_upgrade;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Host $host$is_request_port$request_port;
proxy_set_header X-Forwarded-Method $request_method; proxy_set_header X-Forwarded-Method $request_method;
proxy_set_header X-Forwarded-Port $server_port; proxy_set_header X-Forwarded-Port $server_port;
proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Proto $scheme;
@@ -33,5 +33,5 @@ proxy_set_header X-Forwarded-Server $host;
proxy_set_header X-Forwarded-Ssl on; proxy_set_header X-Forwarded-Ssl on;
proxy_set_header X-Forwarded-Uri $request_uri; proxy_set_header X-Forwarded-Uri $request_uri;
proxy_set_header X-Original-Method $request_method; proxy_set_header X-Original-Method $request_method;
proxy_set_header X-Original-URL $scheme://$host:$server_port$request_uri; proxy_set_header X-Original-URL $scheme://$host$is_request_port$request_port$request_uri;
proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Real-IP $remote_addr;
@@ -12,7 +12,7 @@ location /tinyauth {
proxy_pass http://$upstream_tinyauth:3000/api/auth/nginx; proxy_pass http://$upstream_tinyauth:3000/api/auth/nginx;
proxy_set_header x-forwarded-proto $scheme; proxy_set_header x-forwarded-proto $scheme;
proxy_set_header x-forwarded-host $host:$server_port; proxy_set_header x-forwarded-host $host$is_request_port$request_port;
proxy_set_header x-forwarded-uri $request_uri; proxy_set_header x-forwarded-uri $request_uri;
} }
@@ -21,7 +21,7 @@ location @tinyauth_login {
internal; internal;
## Set the $target_url variable based on the original request ## Set the $target_url variable based on the original request
set_escape_uri $target_url $scheme://$host:$server_port$request_uri; set_escape_uri $target_url $scheme://$host$is_request_port$request_port$request_uri;
## Set the $signin_url variable ## Set the $signin_url variable
set $domain $host; set $domain $host;