Fix: Adding trust proxies, since file downloading cannot work, traffic in Laravel is plain HTTP, the file signed-route generation throws 401

This commit is contained in:
2026-09-30 09:48:12 +03:00
parent 72ff4e5c76
commit e3f9b3deb1
+12
View File
@@ -11,6 +11,18 @@
health: '/up',
)
->withMiddleware(function (Middleware $middleware): void {
// nginx (docker/nginx/prod.conf) only listens on plain HTTP:80.
// Without trusting that layer's X-Forwarded-Proto header, Laravel sees every
// request as http://, so url()/signed-route generation and
// verification (URL::hasValidSignature()) both use the wrong
// scheme — breaks any signed URL whose recipient hits it over
// https (e.g. Modules\Core\Shipping\Http\Controllers\
// DownloadShipmentLabelController's label links) with a 401.
// '*' trusts whatever's immediately upstream, since that's
// container-to-container inside the same deploy, not arbitrary
// public traffic.
$middleware->trustProxies(at: '*');
// Laravel's priority list would otherwise run `auth` before core's
// `locale` middleware, so the redirects below would build URLs before
// URL::defaults(['locale' => …]) is set, throwing a missing-parameter error.