diff --git a/scripts/tests/web-base-path-nginx-smoke-test.sh b/scripts/tests/web-base-path-nginx-smoke-test.sh index 446f3fff..2fade867 100755 --- a/scripts/tests/web-base-path-nginx-smoke-test.sh +++ b/scripts/tests/web-base-path-nginx-smoke-test.sh @@ -86,6 +86,11 @@ if [ "$code" != '301' ]; then echo "bare prefix must 301-redirect, got: $code" >&2 exit 1 fi +location=$(curl -s -o /dev/null -D - "$base/skillhub" | awk 'tolower($1) == "location:" { print $2 }' | tr -d '\r') +if [ "$location" != '/skillhub/' ]; then + echo "bare prefix redirect must stay relative to preserve an upstream HTTPS scheme, got: $location" >&2 + exit 1 +fi docker rm -f "$name" >/dev/null 2>&1 || true diff --git a/web/docker-entrypoint.d/20-base-path.sh b/web/docker-entrypoint.d/20-base-path.sh index 04a60ce3..2e895d3f 100644 --- a/web/docker-entrypoint.d/20-base-path.sh +++ b/web/docker-entrypoint.d/20-base-path.sh @@ -96,7 +96,7 @@ if [ "$SKILLHUB_WEB_BASE_PATH" = / ]; then >"$routing_config" else base_path_without_trailing_slash=${SKILLHUB_WEB_BASE_PATH%/} - printf 'set $skillhub_forwarded_prefix %s;\n\nlocation = %s {\n return 301 %s/;\n}\n\nlocation ^~ %s {\n rewrite ^%s(.*)$ /$1 last;\n}\n' \ + printf 'set $skillhub_forwarded_prefix %s;\n\nlocation = %s {\n absolute_redirect off;\n return 301 %s/;\n}\n\nlocation ^~ %s {\n rewrite ^%s(.*)$ /$1 last;\n}\n' \ "$base_path_without_trailing_slash" \ "$base_path_without_trailing_slash" \ "$base_path_without_trailing_slash" \