Next
Public origin
Resolving the canonical public origin behind proxies and locale domains.
On this page
@systhemaui/next/origin answers "which of this site's origins did a request arrive on" without trusting the request. It is server-safe and has no imports.
UsageLink to this section
import { getSysthemaPublicOrigins, resolveSysthemaPublicOrigin } from '@systhemaui/next/origin'
getSysthemaPublicOrigins() // ['https://example.com', 'https://example.de']
resolveSysthemaPublicOrigin(request) // 'https://example.de' on the German domainHow origins are resolvedLink to this section
getSysthemaPublicOrigins()lists the origin ofNEXT_PUBLIC_SERVER_URLfirst, then each distinct locale domain from the contractwithSysthemainjects (SYSTHEMA_LOCALES).resolveSysthemaPublicOrigin(request)checksx-forwarded-host(first entry), thenhost. The first one naming an allowed origin wins, and the origin is returned as configured, scheme included. A host that is not allowed, or carries anything other thanhostname[:port](whitespace, CR/LF, a path, credentials), falls back to the origin ofNEXT_PUBLIC_SERVER_URL, or''when it is unset.x-forwarded-protois never read.- Both take an optional
{ serverURL, locales }to override the environment, for tests or a non-Systhema config.
When to use itLink to this section
Use it wherever a response names the site and may be cached, such as the scaffolded robots.txt route's Sitemap: line. Host and X-Forwarded-* are client-controlled, and a CDN does not key its cache on X-Forwarded-Host, so echoing them lets one forged request poison the cached response.