Take the public domain from X-Forwarded-Host when set #3

Merged
jk merged 1 commit from forwarded-host into main 2026-09-28 10:49:26 +00:00
Member

Follow-up to #2. Apps that proxy with their own HTTP client send the upstream address as Host, so the callback came out as https://192.168.4.12:7233/.... Now the server uses X-Forwarded-Host if it's set and falls back to Host.

Each app must send X-Forwarded-Host: <its domain> when it calls lnurl. The server trusts the header, so it must only be reachable over the tailnet.

Tested with go vet ./... and go test ./.... There's a new test for a callback built from X-Forwarded-Host.

🤖 Generated with Claude Code

Follow-up to #2. Apps that proxy with their own HTTP client send the upstream address as `Host`, so the callback came out as `https://192.168.4.12:7233/...`. Now the server uses `X-Forwarded-Host` if it's set and falls back to `Host`. Each app must send `X-Forwarded-Host: <its domain>` when it calls lnurl. The server trusts the header, so it must only be reachable over the tailnet. Tested with `go vet ./...` and `go test ./...`. There's a new test for a callback built from `X-Forwarded-Host`. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Apps that proxy with their own HTTP client send the upstream address as
Host, so they pass their domain in X-Forwarded-Host instead.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
jk merged commit 16a283c1a3 into main 2026-09-28 10:49:26 +00:00
jk deleted branch forwarded-host 2026-09-28 10:49:26 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
unbeholden/lnurl-server!3
No description provided.