Forward the login host so recovery can resolve the org

Featurekamo-login
Shipped
August 6, 2026 at 9:42 PM UTC
Author
Kamo
Commit
7b48663

Password recovery now accepts a member's primary mailbox address, which only names an account within one org. This proxy reaches SecurityService over cluster DNS, so Host is the service name and the browser's host has to travel in X-Forwarded-Host — the only header the backend reads it from. `login` is a registered alias, so login.acme.com resolves to the acme.com org as-is; no rewrite to api.*, which is the APIService gateway's requirement and this route bypasses it.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing