Fix asset URLs generated as http:// behind staging's reverse proxy
PHP Tests / php-tests (push) Has been cancelled

Staging terminates SSL at a reverse proxy in front of the app, but
Laravel had no trustProxies() configured, so it never saw the request
as HTTPS and generated http:// asset URLs on the https:// page.
Browsers block that as mixed content, which silently broke every
JS-enhanced Filament field (FileUpload, Textarea, etc.) — e.g. the
Ev Company logo field falling back to a bare native file input.

- bootstrap/app.php: trust the proxy via X-Forwarded-* headers.
- AppServiceProvider: force the https scheme when APP_URL is https,
  as a fallback in case the forwarded header is ever missing.
This commit is contained in:
Nyan Lin Paing
2026-08-23 23:19:44 +07:00
parent da6d51b7b2
commit 98dacef556
2 changed files with 28 additions and 0 deletions
+17
View File
@@ -11,6 +11,7 @@ use Illuminate\Http\Request;
use Illuminate\Validation\ValidationException;
use Modules\Identity\Http\Middleware\AuthenticateSanctumOrFastApiJwt;
use Modules\Identity\Http\Middleware\EnsureFastApiAgent;
use Symfony\Component\HttpFoundation\Request as SymfonyRequest;
use Symfony\Component\HttpKernel\Exception\HttpExceptionInterface;
use Symfony\Component\HttpKernel\Exception\MethodNotAllowedHttpException;
use Symfony\Component\HttpKernel\Exception\NotFoundHttpException;
@@ -24,6 +25,22 @@ return Application::configure(basePath: dirname(__DIR__))
health: '/up',
)
->withMiddleware(function (Middleware $middleware): void {
// Staging/production sit behind a reverse proxy/load balancer that
// terminates SSL — without this, Laravel never sees the original
// request as HTTPS, so it generates http:// asset URLs, which
// browsers then block as mixed content on the https:// page (e.g.
// Filament's file-upload.js failing to load, breaking that field's
// JS-enhanced dropzone). Trusting '*' is the standard Laravel
// pattern when the proxy's IP isn't fixed/known in advance.
$middleware->trustProxies(
at: '*',
headers: SymfonyRequest::HEADER_X_FORWARDED_FOR
| SymfonyRequest::HEADER_X_FORWARDED_HOST
| SymfonyRequest::HEADER_X_FORWARDED_PORT
| SymfonyRequest::HEADER_X_FORWARDED_PROTO
| SymfonyRequest::HEADER_X_FORWARDED_AWS_ELB,
);
$middleware->alias([
'fastapi.agent' => EnsureFastApiAgent::class,
'api.auth' => AuthenticateSanctumOrFastApiJwt::class,