You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix: Update authorization header handling for same-origin proxy in API request - #366
This pull request introduces changes to improve authentication handling and reverse proxy configuration for both the chat-app and scenario-app frontends. The main goals are to support secure token forwarding when using a same-origin proxy, ensure proper audience validation for Azure AD tokens, and correctly propagate authorization headers through Nginx. Below are the most important changes:
Authentication Header Handling:
Updated both chat-app and scenario-app frontend code (EnhancedChatPanel.tsx, api.ts) to dynamically set the authentication header to X-Backend-Authorization when requests are proxied through the same origin, otherwise using the standard Authorization header. This ensures tokens are securely forwarded through the frontend proxy. [1][2][3][4]
Reverse Proxy Configuration:
Modified Nginx startup scripts (startup.sh) for both apps to forward the Authorization header from X-Backend-Authorization to the backend, ensuring authentication tokens are properly relayed to backend services. [1][2][3]
Added proxy_redirect rules in Nginx to correctly rewrite backend redirects to the frontend domain, improving compatibility with backend responses. [1][2]
Azure AD Authentication Audience Validation:
Updated Azure AD configuration scripts (configure_auth.ps1, configure_auth.sh) to include both the client ID and api://<client_id> as allowed audiences, ensuring tokens issued for either identifier are accepted by the backend. [1][2]
These changes collectively enhance authentication security and reliability when deploying behind a reverse proxy and using Azure AD for authentication.
Does this introduce a breaking change?
Yes
No
How to Test
Get the code
git clone [repo-address]
cd [repo-name]
git checkout [branch-name]
npm install
This equality check also misses equivalent same-origin bases with a trailing slash or relative path. The TTS request then uses Authorization, which the proxy overwrites from the missing custom header, causing an authenticated request to arrive without credentials. Use URL-origin comparison consistently with the chat frontend.
Use URL-origin comparison for same-origin authorization handling
scenario-app/frontend/src/lib/api.ts:68
Same-origin detection by string equality misclassifies equivalent bases such as https://host/ or /. In that case this sends Authorization, but the same-origin Nginx proxy replaces upstream Authorization from the absent X-Backend-Authorization header, so authenticated API calls reach the backend without a token. Resolve the base URL and compare origins as the chat frontend does.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
This pull request introduces changes to improve authentication handling and reverse proxy configuration for both the
chat-appandscenario-appfrontends. The main goals are to support secure token forwarding when using a same-origin proxy, ensure proper audience validation for Azure AD tokens, and correctly propagate authorization headers through Nginx. Below are the most important changes:Authentication Header Handling:
chat-appandscenario-appfrontend code (EnhancedChatPanel.tsx,api.ts) to dynamically set the authentication header toX-Backend-Authorizationwhen requests are proxied through the same origin, otherwise using the standardAuthorizationheader. This ensures tokens are securely forwarded through the frontend proxy. [1] [2] [3] [4]Reverse Proxy Configuration:
startup.sh) for both apps to forward theAuthorizationheader fromX-Backend-Authorizationto the backend, ensuring authentication tokens are properly relayed to backend services. [1] [2] [3]proxy_redirectrules in Nginx to correctly rewrite backend redirects to the frontend domain, improving compatibility with backend responses. [1] [2]Azure AD Authentication Audience Validation:
configure_auth.ps1,configure_auth.sh) to include both the client ID andapi://<client_id>as allowed audiences, ensuring tokens issued for either identifier are accepted by the backend. [1] [2]These changes collectively enhance authentication security and reliability when deploying behind a reverse proxy and using Azure AD for authentication.
Does this introduce a breaking change?
How to Test
What to Check
Verify that the following are valid
Other Information