Skip to content

Honor forwarded HTTPS for CoinPay PKCE cookies - #31

Merged
ralyodio merged 1 commit into
moshcoder:masterfrom
aiirvizionz:clientkit/secure-coinpay-pkce-cookies
Jul 13, 2026
Merged

Honor forwarded HTTPS for CoinPay PKCE cookies#31
ralyodio merged 1 commit into
moshcoder:masterfrom
aiirvizionz:clientkit/secure-coinpay-pkce-cookies

Conversation

@aiirvizionz

Copy link
Copy Markdown
Contributor

Summary

  • detect HTTPS for CoinPay login PKCE cookies from the incoming request and x-forwarded-proto
  • keep explicit forwarded HTTP as non-secure for local/proxy test cases
  • retain the existing APP_BASE_URL fallback for direct deployments

Validation

  • tsc --noEmit
  • git diff --check

@ralyodio
ralyodio merged commit 82e5afa into moshcoder:master Jul 13, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants