* fix(branding): render tenant logos unoptimized so self-hosted sidebars work (#2203) On the official Docker image a byrå logo uploaded under Settings > Brand worked as favicon but rendered broken in the sidebar. BrandHomeLink (and BrandWordmark) sent the Supabase Storage URL through the Next.js image optimizer, whose remote-host allowlist is derived from NEXT_PUBLIC_SUPABASE_URL at BUILD time. The generic image bakes a sentinel there and docker-entrypoint.sh substitutes the real URL only at container start, so /_next/image answered 400 '"url" parameter is not allowed'. Both tenant-logo <Image> elements now pass `unoptimized`: the browser fetches the public object directly, which is exactly what the favicon already did, and CSP img-src already permits https:. The remotePatterns block in next.config.ts stays for builds that know the URL, with its comment updated to say what it still covers. Closes #2203 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VnConrmMCxJRQ5kfiPPWyy * chore: carry the DECISIONS.md line for this PR in #2247 instead (append-only log conflicts on every merge) --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5.1
Jakob Wennberg
parent
cc18e9d530
commit
e66195e5bb
@@ -38,6 +38,16 @@ export function BrandHomeLink({ showLabel = false }: { showLabel?: boolean }) {
|
||||
width={26}
|
||||
height={26}
|
||||
className="h-[26px] w-[26px] rounded-lg object-contain"
|
||||
// Tenant logos live on the deployment's Supabase Storage host, and
|
||||
// the image optimizer only allows that host when
|
||||
// NEXT_PUBLIC_SUPABASE_URL was known at BUILD time. The generic
|
||||
// Docker image bakes a sentinel and substitutes the real URL at
|
||||
// container start, so on self-hosted installs /_next/image answered
|
||||
// 400 '"url" parameter is not allowed' and the sidebar mark rendered
|
||||
// broken while the favicon (same URL, no optimizer) worked (issue
|
||||
// #2203). The browser fetches the public object directly instead; at
|
||||
// 26px there is nothing to optimize anyway.
|
||||
unoptimized
|
||||
/>
|
||||
) : (
|
||||
<Image
|
||||
|
||||
@@ -49,6 +49,10 @@ export function BrandWordmark({
|
||||
height={size === 'hero' ? 64 : 22}
|
||||
className={cn('w-auto', size === 'hero' ? 'h-16' : 'h-[22px]')}
|
||||
priority={size === 'hero'}
|
||||
// Bypass the image optimizer: its remote-host allowlist is fixed at
|
||||
// build time, which the runtime-configured Docker image cannot
|
||||
// satisfy (issue #2203, same reasoning as BrandHomeLink).
|
||||
unoptimized
|
||||
/>
|
||||
</span>
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user