fix(auth) : bind Sudloh sessions and stop OAuth redirect loops
CI / Verify (push) Successful in 1m31s
CI / Build immutable images and deploy (push) Successful in 2m4s

This commit is contained in:
2026-10-06 14:28:59 +07:00 Unverified
parent 2f69115a91
commit 445865bf42
13 changed files with 212 additions and 21 deletions
+3 -2
View File
@@ -10,8 +10,9 @@ data:
SUDLOH_OIDC_ISSUER: https://account.sudloh.com/api/auth
SUDLOH_OIDC_REDIRECT_URI: https://guide.sudloh.com/api/auth/callback/sudloh
SUDLOH_OIDC_ONLY: "true"
# Traefik must overwrite this header; do not expose the app directly.
TRUSTED_CLIENT_IP_HEADER: x-real-ip
# Traefik supplies X-Forwarded-For and does not trust incoming forwarded headers.
# The network policy allows only Traefik to reach the app.
TRUSTED_CLIENT_IP_HEADER: x-forwarded-for
DATABASE_POOL_SIZE: "10"
HEALTHCHECK_TIMEOUT_MS: "2500"
NEXT_DEPLOYMENT_ID: replace-me