Files
picpeak/docs/nginx-fix.md
T
paul 605f773a7e
Test and Lint / backend-test (push) Successful in 1m13s
continuous-integration/drone/push Build is passing
Test and Lint / frontend-test (push) Successful in 2m11s
Version and Release / version-bump (push) Successful in 34s
Version and Release / trigger-drone (push) Successful in 3s
fix: resolve gallery photo/thumbnail serving issues
- Change gallery photo URLs from static paths to API endpoints
- Add dedicated thumbnail serving endpoint for galleries
- Add test script to diagnose authentication issues
- Add nginx configuration documentation for Authorization header

This fixes the issue where photos and thumbnails work in admin but not
in gallery view. The problem was that static file routes with auth
middleware often have Authorization headers stripped by reverse proxies.
Using API endpoints ensures proper authentication handling.

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-15 11:47:53 +02:00

1.5 KiB

Nginx Configuration Fix for Photo Authentication

If photos and thumbnails are not loading in gallery view but work in admin, it's likely that the Authorization header is being stripped by nginx or another reverse proxy.

Common Issue

The Authorization header is often not passed through by default in nginx proxy configurations.

Fix

Add these lines to your nginx configuration for the PicPeak location block:

location / {
    proxy_pass http://localhost:3001;
    
    # Important: Pass the Authorization header
    proxy_pass_header Authorization;
    proxy_set_header Authorization $http_authorization;
    
    # Other standard proxy headers
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
}

Alternative Fix Using Traefik

If using Traefik, ensure headers are passed:

services:
  picpeak:
    labels:
      - "traefik.http.middlewares.picpeak-headers.headers.customrequestheaders.Authorization="

Testing

  1. Check if Authorization header is reaching the backend:

    curl -H "Authorization: Bearer YOUR_TOKEN" https://picpeak.yourdomain.com/thumbnails/test.jpg -v
    
  2. Check nginx logs to see if the header is present:

    tail -f /var/log/nginx/access.log
    

Docker Compose Fix

If using docker-compose with nginx proxy, add:

environment:
  - NGINX_PROXY_PASS_HEADER=Authorization