What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
If every route starts returning HTTP 500 after a site is placed behind a CDN and a second reverse proxy, inspect the forwarding headers at the application boundary. In one documented Next.js and Auth.js v5 beta deployment, both proxies contributed https to X-Forwarded-Proto. The application received https, https, used it to build a session URL, and threw TypeError: Invalid URL before the route’s own logic ran. That case explains one way a proxy chain can cause site-wide failures; it does not mean every multi-proxy setup will fail the same way.
How two proxy values can turn into a site-wide 500
In the reported setup, a browser request passed through a CDN and an origin web server before reaching a Node application. The CDN set X-Forwarded-Proto: https; the origin server, which also received HTTPS traffic, added its own value. Depending on the proxy behavior, repeated header lines may arrive separately or be combined as a comma-separated value.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
WatchGuard Firebox M295 High Availability Unit with 3 Year Standard Support - HA Device for... | $2,185.11 | Buy on Amazon |
The case author, Mahmut Gündüzalp, reported that Fetch’s Headers.get() exposed repeated values as one comma-separated string. The application used the Auth.js v5 beta auth() middleware wrapper. With no AUTH_URL configured, the reported URL-construction path read x-forwarded-host and x-forwarded-proto, then passed a constructed address to new URL(). A single https scheme could produce a valid HTTPS URL; the combined value produced an invalid address such as https, https://example.org and raised TypeError: Invalid URL.
Because the wrapper ran on every matched request, the exception occurred even on routes that did not otherwise need session data. The case author says the issue was not reproduced on a development machine without the proxy chain, and reports re-measuring the behavior against the deployed library build. This is evidence about that described stack and build, not a guarantee about other releases or frameworks. Read the incident account by Mahmut Gündüzalp.
#1 Best Overall
- High Availability (HA) redundant unit for resilient failover and uptime. Operates only as the secondary in an HA pair and must be paired with a primary WatchGuard Firebox of the same model for synchronization and failover. Not a standalone appliance.
- WatchGuard Firebox M295 High Availability Unit with 3 Year Standard Support License (WGM29501603) - The Firebox M295 combines enterprise-grade security with multi-gig connectivity, SD-WAN, TLS decryption, and proxy-based inspection in a compact rackmount design.
- Standard Support covers software updates and round-the-clock emergency help. Add a Basic or Total Security Suite to activate IPS, gateway antivirus, and web filtering so threats are blocked before they reach users.
- Standard Support provides reliable technical assistance and software updates for WatchGuard Firebox appliances. Offering 24x7 help for emergencies and business-hours support for routine needs, it ensures your network stays secure and operational.
- Interfaces and continuity: 4x 2.5Gb RJ45, 4x 1Gb RJ45, 2x 10Gb SFP+ with VLANs and link aggregation, plus RIP, OSPF, BGP, and high availability to keep sites online.
Why forwarded headers can contain multiple values
Forwarding metadata describes what a proxy observed or how a request arrived; it is not automatically a single, trustworthy value. RFC 7239 specifies the standardized Forwarded header and allows successive proxies to append information as another comma-separated value or another field. It also warns that forwarding information may be changed by any node on the route, including the client. RFC 7239: Forwarded HTTP Extension.
The incident concerns the commonly used X-Forwarded-Proto and X-Forwarded-Host headers, not a universal parsing rule for every proxy or framework. Implementations differ in whether they overwrite, preserve, or append values, and in how application code interprets them. Do not assume that taking the first or last comma-separated item is correct: the right value depends on the trusted proxy boundary and the origin semantics your application needs.
Trace the headers and middleware in order
- Capture what reaches the application. Log the value and multiplicity of
X-Forwarded-ProtoandX-Forwarded-Hostat the application boundary. Check whether repeated field lines have become a comma-separated string. Redact or otherwise protect sensitive host and request data in logs. - Map each hop. Record whether the CDN and origin server set, append, preserve, or overwrite forwarding metadata. Verify what each hop sends rather than inferring behavior from its configuration label.
- Find code that constructs absolute URLs. Check authentication and session middleware, as well as any other code that reads forwarded scheme or host values. Confirm the behavior for the exact framework and library versions deployed.
- Establish which proxy is trusted. Configure the application and proxies so client-supplied forwarding values are not treated as authoritative unless they arrive through a trusted boundary. RFC 7239 explains why these values cannot inherently be relied on as correct.
- Trace the whole middleware chain after changing the origin. If an explicit public origin makes URL construction succeed, inspect later redirects and rewrites to see whether they use that public address or an internal request origin.
- Compare application and proxy logs. Identify whether the application threw an exception or a gateway received an invalid upstream response before choosing a fix based on the status code.
Why setting an explicit origin can cause a second failure
In the reported deployment, setting AUTH_URL=https://example.org avoided the invalid-URL error by giving Auth.js an explicit origin. But the wrapper then rebuilt the request using that public origin. A later internationalization middleware derived a rewrite from req.url, sending the rewrite back through the public address and CDN and creating a loop.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallThat is a specific observed trade-off, not a claim that configuring an explicit origin is always unsafe. Before applying this workaround, trace how downstream middleware builds redirect and rewrite targets. A change that repairs session URL construction can alter the request origin seen by later code.
What HTTP 500 and 502 do—and do not—tell you
HTTP 500 means the server encountered an unexpected condition that prevented it from fulfilling the request. HTTP 502 means a gateway or proxy received an invalid response from an upstream server. Either status is a symptom, not a diagnosis: inspect the application exception and the proxy’s upstream logs to locate where the failure occurred. The 500 definition is also stated in the legacy HTTP/1.1 specification, RFC 2616. RFC 2616: Hypertext Transfer Protocol — HTTP/1.1.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

