Skip to content

fix(github): use public URL for OAuth + manifest callback redirects - #10

Merged
ralyodio merged 1 commit into
masterfrom
fix/github-callback-public-url
May 22, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/github-callback-public-url

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Summary

Root cause for the `https://0.0.0.0:8080/...\` redirects that kept showing up after the "App created" step. Behind Railway's reverse proxy, Next.js's `request.url` reports the internal bind address, not the public URL. `new URL(path, request.url)` therefore baked `0.0.0.0:8080` into every Location header — including the one that lands the admin on the secrets page.

PR #8 already fixed this for the manifest builder. This PR fixes it for the two callback handlers I missed:

  • `/api/github/setup-callback` — redirect to `/admin/github/setup/done` after the App-manifest conversion.
  • `/api/github/callback` — redirect to `/settings/integrations/github` after a user installs the App.

Helper

New `lib/request-url.ts` with `publicBaseUrlFromHeaders()` + `publicUrl()` — reads `x-forwarded-host` + `x-forwarded-proto` (added by Railway's proxy), with a safety net that ignores any `0.0.0.0 / 127.0.0.1 / localhost` so those can never end up in a Location header.

Test plan

After merge + deploy:

🤖 Generated with Claude Code

Behind Railway's reverse proxy, Next.js's request.url reports the
internal bind address (e.g. http://0.0.0.0:8080/...), not the public
URL. Using `new URL(path, request.url)` to build redirect Location
headers therefore sent users to the bind address — visible to the
admin during the App-manifest "App created" redirect.

Adds lib/request-url.ts with publicBaseUrlFromHeaders() and publicUrl()
helpers that read x-forwarded-host + x-forwarded-proto (Railway's
proxy adds these), ignoring 0.0.0.0 / 127.0.0.1 / localhost so they
can never be baked into a Location.

Patched both callbacks to use publicUrl():
- /api/github/setup-callback: post-manifest redirect to /admin/github/setup/done
- /api/github/callback: post-install redirect to /settings/integrations/github

The /admin/github/setup manifest builder already had its own equivalent
fix in PR #8 (publicBaseUrl()); the callback redirects were missed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@ralyodio
ralyodio merged commit c81f86f into master May 22, 2026
@ralyodio
ralyodio deleted the fix/github-callback-public-url branch May 22, 2026 13:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant