Docs
Next

Public origin

Resolving the canonical public origin behind proxies and locale domains.

On this page

@systhemaui/next/origin answers "which of this site's origins did a request arrive on" without trusting the request. It is server-safe and has no imports.

UsageLink to this section

import { getSysthemaPublicOrigins, resolveSysthemaPublicOrigin } from '@systhemaui/next/origin'

getSysthemaPublicOrigins() // ['https://example.com', 'https://example.de']
resolveSysthemaPublicOrigin(request) // 'https://example.de' on the German domain

How origins are resolvedLink to this section

  • getSysthemaPublicOrigins() lists the origin of NEXT_PUBLIC_SERVER_URL first, then each distinct locale domain from the contract withSysthema injects (SYSTHEMA_LOCALES).
  • resolveSysthemaPublicOrigin(request) checks x-forwarded-host (first entry), then host. The first one naming an allowed origin wins, and the origin is returned as configured, scheme included. A host that is not allowed, or carries anything other than hostname[:port] (whitespace, CR/LF, a path, credentials), falls back to the origin of NEXT_PUBLIC_SERVER_URL, or '' when it is unset. x-forwarded-proto is never read.
  • Both take an optional { serverURL, locales } to override the environment, for tests or a non-Systhema config.

When to use itLink to this section

Use it wherever a response names the site and may be cached, such as the scaffolded robots.txt route's Sitemap: line. Host and X-Forwarded-* are client-controlled, and a CDN does not key its cache on X-Forwarded-Host, so echoing them lets one forged request poison the cached response.