feat(auth): configure trustedOrigins for CSRF protection

Add trustedOrigins to better-auth config to ensure proper origin
validation behind reverse proxy.
This commit is contained in:
2026-04-06 23:18:20 -04:00
parent ece03a9124
commit 4c6f880a3f

View File

@@ -24,6 +24,7 @@ if (!process.env.AUTH_AUTHENTIK_ISSUER) {
export const auth = betterAuth({ export const auth = betterAuth({
secret: process.env.BETTER_AUTH_SECRET, secret: process.env.BETTER_AUTH_SECRET,
baseURL: process.env.BETTER_AUTH_URL, baseURL: process.env.BETTER_AUTH_URL,
trustedOrigins: [process.env.BETTER_AUTH_URL],
database: drizzleAdapter(db, { database: drizzleAdapter(db, {
provider: "pg", provider: "pg",
schema, schema,