Workaround · Self-hosting & upgrades · Blocks work
Auth secure session behind reverse proxy needs trusted proxy config
1 source thread · first seen 2025-09
Summary
A maintainer workaround explains that secure sessions behind a reverse proxy require enabling the Koa proxy setting and forwarding the right headers, which is not set up by default.
- Affects
- Teams running Strapi behind a reverse proxy
- Workaround
- Set the proxy option in server config and forward x-forwarded headers from the proxy
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“At minimum your reverse proxy should be passing along the `x-forwarded-for` and `x-forwarded-proto` headers”