Skip to content

fix(next-auth): do not assume x-forwarded-proto on server actions - #13492

Open
RealBhupesh wants to merge 1 commit into
nextauthjs:mainfrom
RealBhupesh:cursor/fix-x-forwarded-proto-c78b
Open

RealBhupesh wants to merge 1 commit into
nextauthjs:mainfrom
RealBhupesh:cursor/fix-x-forwarded-proto-c78b

Conversation

@RealBhupesh

Copy link
Copy Markdown

Summary

On Next.js 16, server actions often omit x-forwarded-proto. signIn / signOut / update / getSession passed headers.get("x-forwarded-proto") into createActionURL, which treats a missing value as https. Local HTTP then fails as a masked Configuration error.

Fix

Add getProtocol() with fallback: AUTH_URL/NEXTAUTH_URL origin, then first hop of x-forwarded-proto, then http in development/test and https in production. Never pass null.

Tests

Unit tests for getProtocol and signIn without x-forwarded-proto.

Fixes #13388

- Add getProtocol() helper to safely derive request protocol
- Fallback order: AUTH_URL/NEXTAUTH_URL > x-forwarded-proto header > http in dev / https in prod
- Handle comma-separated x-forwarded-proto values (use first value)
- Remove @ts-expect-error comments for nullable proto
- Add regression tests for missing x-forwarded-proto scenarios

Fixes nextauthjs#13388

Co-authored-by: Bhupesh Cholake <realbhupesh@gmail.com>
@vercel

vercel Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
auth-docs Ready Ready Preview Sep 1, 2026 12:02pm UTC
1 Skipped Deployment
Project Deployment Actions Updated
next-auth-docs Ignored Ignored Preview Sep 1, 2026 12:02pm UTC

Request Review

@vercel

vercel Bot commented Sep 1, 2026

Copy link
Copy Markdown

@cursoragent is attempting to deploy a commit to the authjs Team on Vercel.

A member of the Team first needs to authorize it.

This branch was successfully deployed

1 active deployment
Preview – auth-docs — 63cfbdb5 Deployed Sep 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

signIn server action fails with Configuration error on Next.js 16

2 participants