Sveltekit: Cross-site POST form submissions are forbidden (another)

577 Views Asked by At

Yeah. me too. I saw posts about it but nothing worked so far. I have a linux server running with a nginx reverse proxy. I redirect sub.domain.com traffic to localhost:3000 which is my sveltekit app.

I use systemd to manage my services. I set the environment variable ORIGIN this is mainly what everyone talks about like:

[Service]
Environment=ORIGIN=https://sub.domain.com

I checked the header of the request. 'Origin' is what it should be. https://sub.domain.com.

I switched from deno adapter to node adapter, because everyone was talking about the node adapter and its ORIGIN env variable.

-- UPDATE --

some more information:

GENERAL HEADERS
Request URL:     https://sub.domain.com/login?/login
Remote Address:  my IP

REQUEST HEADERS
Host:    sub.domain.com
Origin:  https://sub.domain.com
Referer: https://sub.domain.com/login

I dont get how is this not the same origin. I played with the ORIGIN env variable. did not seem to change anything tho.

0

There are 0 best solutions below