diff --git a/bootstrap/app.php b/bootstrap/app.php index 2957643..93c0d3e 100644 --- a/bootstrap/app.php +++ b/bootstrap/app.php @@ -6,11 +6,23 @@ return Application::configure(basePath: dirname(__DIR__)) ->withRouting( - web: __DIR__.'/../routes/web.php', - commands: __DIR__.'/../routes/console.php', + web: __DIR__ . '/../routes/web.php', + commands: __DIR__ . '/../routes/console.php', health: '/up', ) ->withMiddleware(function (Middleware $middleware): void { + // nginx (docker/nginx/prod.conf) only listens on plain HTTP:80. + // Without trusting that layer's X-Forwarded-Proto header, Laravel sees every + // request as http://, so url()/signed-route generation and + // verification (URL::hasValidSignature()) both use the wrong + // scheme — breaks any signed URL whose recipient hits it over + // https (e.g. Modules\Core\Shipping\Http\Controllers\ + // DownloadShipmentLabelController's label links) with a 401. + // '*' trusts whatever's immediately upstream, since that's + // container-to-container inside the same deploy, not arbitrary + // public traffic. + $middleware->trustProxies(at: '*'); + // Laravel's priority list would otherwise run `auth` before core's // `locale` middleware, so the redirects below would build URLs before // URL::defaults(['locale' => …]) is set, throwing a missing-parameter error. @@ -21,8 +33,8 @@ // Both resolve inside the {locale} group, after the `locale` middleware // has set URL::defaults(['locale' => …]), so route() needs no locale arg. - $middleware->redirectGuestsTo(fn () => route('login')); - $middleware->redirectUsersTo(fn () => route('home')); + $middleware->redirectGuestsTo(fn() => route('login')); + $middleware->redirectUsersTo(fn() => route('home')); }) ->withExceptions(function (Exceptions $exceptions): void { //