Friction

Workaround · Self-hosting & upgrades · Blocks work

Auth secure session behind reverse proxy needs trusted proxy config

1 source thread · first seen 2025-09

Summary

A maintainer workaround explains that secure sessions behind a reverse proxy require enabling the Koa proxy setting and forwarding the right headers, which is not set up by default.

Affects
Teams running Strapi behind a reverse proxy
Workaround
Set the proxy option in server config and forward x-forwarded headers from the proxy

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“At minimum your reverse proxy should be passing along the `x-forwarded-for` and `x-forwarded-proto` headers”

Report this item