---
title: "Public origin"
description: "Resolving the canonical public origin behind proxies and locale domains."
requested_language: fr
language: en
translation_notice: "This page isn't translated yet"
url: https://docs.systhema.app/fr/nextjs/public-origin
version: unreleased (main)
docs_index: https://docs.systhema.app/fr/llms.txt
---
> This page isn't translated yet. Showing English.


`@systhemaui/next/origin` answers "which of this site's origins did a request arrive on" without trusting the request. It is server-safe and has no imports.

## Usage

```ts
import { getSysthemaPublicOrigins, resolveSysthemaPublicOrigin } from '@systhemaui/next/origin'

getSysthemaPublicOrigins() // ['https://example.com', 'https://example.de']
resolveSysthemaPublicOrigin(request) // 'https://example.de' on the German domain
```

## How origins are resolved

- `getSysthemaPublicOrigins()` lists the origin of `NEXT_PUBLIC_SERVER_URL` first, then each distinct locale domain from the contract `withSysthema` injects (`SYSTHEMA_LOCALES`).
- `resolveSysthemaPublicOrigin(request)` checks `x-forwarded-host` (first entry), then `host`. The first one naming an allowed origin wins, and the origin is returned as configured, scheme included. A host that is not allowed, or carries anything other than `hostname[:port]` (whitespace, CR/LF, a path, credentials), falls back to the origin of `NEXT_PUBLIC_SERVER_URL`, or `''` when it is unset. `x-forwarded-proto` is never read.
- Both take an optional `{ serverURL, locales }` to override the environment, for tests or a non-Systhema config.

## When to use it

Use it wherever a response names the site and may be cached, such as the scaffolded `robots.txt` route's `Sitemap:` line. `Host` and `X-Forwarded-*` are client-controlled, and a CDN does not key its cache on `X-Forwarded-Host`, so echoing them lets one forged request poison the cached response.

## Related

- [Public URL recipes](https://docs.systhema.app/fr/nextjs/locales/url-recipes.md)
- [Gateway and status codes](https://docs.systhema.app/fr/nextjs/gateway.md)
