# Shopware hinter Reverse Proxy nutzt http statt https

**URL:** <https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323>\
**Category:** Administration\
**Created:** [20. September 2023 um 19:59 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323 "2023-09-20T19:59:27Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![CRUGG](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/crugg/32/21800_2.png) [@CRUGG](https://forum.shopware.com/u/CRUGG)\
**Post date:** [20. September 2023 um 19:59 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/1 "2023-09-20T19:59:27Z")

</div>

Hallo,

Ich habe einen Docker Container mit:

- apache2 auf Port 888 (ohne SSL) und Shopware 6

und einen weiteren mit:

- einem Caddy Webserver der als Reverse Proxy dient und auf Port 80 und 443 läuft (80 ausschließlich als Redirect von HTTP =\> HTTPS)

Während dem Installationsprozess wird nun ein Request an [http://store.example.com/installer/database-migrate](http://store.example.com/installer/database-migrate) gemacht, was eh erstmal kein Browser zulässt (da es sich hierbei um HTTP handelt, aber der Installer ja über HTTPS aufgerufen ist)

Wie kann ich dafür sorgen, dass Shopware auch wenn es selber nicht direkt mit HTTPS läuft (da es ja erst über den Reverse Proxy kommt) trotzdem https:// statt http:// benutzt?

Edit: `APP_URL` und `STOREFRONT_PROXY_URL` in der `.env` sind bereits auf `https://store.example.com` gesetzt.

---

<div class="post-metadata">

**Author:** ![nets](https://avatars.discourse-cdn.com/v4/letter/n/c68b51/32.png) [@nets](https://forum.shopware.com/u/nets)\
**Post date:** [24. März 2024 um 15:14 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/2 "2024-03-24T15:14:10Z")

</div>

Hi, das ist zwar Lösung für das Problem aber ich habe ein ähnliches Setup mit Caddy als reverse proxy und erhalte einen mixed content Fehler, konntest du das Problem in der Zwischenzeit lösen?

Wenn ja, wie genau?

---

<div class="post-metadata">

**Author:** ![MBDealer](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/mbdealer/32/27217_2.png) [@MBDealer](https://forum.shopware.com/u/MBDealer)\
**Post date:** [25. März 2024 um 06:09 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/3 "2024-03-25T06:09:19Z")

</div>

Hast du TRUSTED\_PROXIES in deiner .env definiert?

---

<div class="post-metadata">

**Author:** ![nets](https://avatars.discourse-cdn.com/v4/letter/n/c68b51/32.png) [@nets](https://forum.shopware.com/u/nets)\
**Post date:** [25. März 2024 um 09:17 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/4 "2024-03-25T09:17:52Z")

</div>

Ja, sowohl in der .env, wie auch in der .env.local, vermutlich ist es nur in der .env.local notwendig, oder?

So sieht das aktuelle Setup aus

 ![traefik](https://europe1.discourse-cdn.com/flex013/uploads/shopware/original/3X/3/4/3431182b1518e2ced36f0afad96a487096efb730.png)

Ohne Caddy als reverse proxy funktioniert es fehlerfrei, das Frontend und Backend wird fehlerfrei geladen, schalte ich Caddy als reverse proxy dazu, tritt der Fehler mit mixed content auf, das Theme wird nicht vollständig geladen.

`.env`

```auto
###> symfony/messenger ###
# Choose one of the transports below
# MESSENGER_TRANSPORT_DSN=amqp://guest:guest@localhost:5672/%2f/messages
# MESSENGER_TRANSPORT_DSN=redis://localhost:6379/messages
# doctrine://default?auto_setup=0
###< symfony/messenger ###

###> symfony/mailer ###
# MAILER_DSN=null://null
###< symfony/mailer ###

###> symfony/lock ###
# Choose one of the stores below
# postgresql+advisory://db_user:db_password@localhost/db_name
LOCK_DSN=flock
###< symfony/lock ###

TRUSTED_PROXIES=127.0.0.1,127.0.0.2,192.168.112.5,192.168.112.6,192.168.112.3,192.168.160.2
#TRUSTED_PROXIES=127.0.0.1,127.0.0.2,192.168.112.5,192.168.112.6,192.168.112.3
TRUSTED_HOSTS=vanill.at,www.vanill.at

###> shopware/core ###
APP_ENV=prod
APP_URL=http://127.0.0.1:8000
APP_SECRET=<redacted>
INSTANCE_ID=<redacted>
BLUE_GREEN_DEPLOYMENT=0
DATABASE_URL=mysql://root:root@localhost/shopware
# With Shopware 6.4.17.0 the MAILER_DSN variable will be used in this template instead of MAILER_URL
MAILER_URL=null://null
###< shopware/core ###

###> shopware/elasticsearch ###
OPENSEARCH_URL=http://localhost:9200
SHOPWARE_ES_ENABLED=0
SHOPWARE_ES_INDEXING_ENABLED=0
SHOPWARE_ES_INDEX_PREFIX=sw
SHOPWARE_ES_THROW_EXCEPTION=1
###< shopware/elasticsearch ###

###> shopware/storefront ###
STOREFRONT_PROXY_URL=http://localhost
SHOPWARE_HTTP_CACHE_ENABLED=1
SHOPWARE_HTTP_DEFAULT_TTL=7200
###< shopware/storefront ###

```

`.env.local`

```auto
APP_SECRET=<redacted>
APP_URL=https://vanill.at
DATABASE_URL=mysql://<redacted>:<redacted>@lcmp-mysql-1:3306/shopwaredb
COMPOSER_HOME=/var/www/html/var/cache/composer
INSTANCE_ID=<redacted>
BLUE_GREEN_DEPLOYMENT=0
OPENSEARCH_URL=http://localhost:9200
ADMIN_OPENSEARCH_URL=http://localhost:9200
TRUSTED_PROXIES=127.0.0.1,127.0.0.2,192.168.112.5,192.168.112.6,192.168.112.3,192.168.160.2
TRUSTED_DOMAINS=vanill.at
TRUSTED_HEADERS='["x-forwarded-for", "x-forwarded-host", "x-forwarded-proto", "x-forwarded-port", "x->

```

Ich habe auch eine `framework.yaml` erstellt in `/srv/lcmp/www/config/packages` , ohne Erfolg (die Datei gab es wider Erwarten nicht im Ordner /packages, habe diese selber erstellt)

```auto
# config/packages/framework.yaml
framework:
    # ...
    # the IP address (or range) of your proxy
    trusted_proxies: '127.0.0.1,127.0.0.2,192.168.112.5,192.168.112.6,192.168.112.3,192.168.160.2'
    # trust *all* "X-Forwarded-*" headers
    trusted_headers: ['x-forwarded-for', 'x-forwarded-host', 'x-forwarded-proto', 'x-forwarded-port',>

```

---

<div class="post-metadata">

**Author:** ![MBDealer](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/mbdealer/32/27217_2.png) [@MBDealer](https://forum.shopware.com/u/MBDealer)\
**Post date:** [25. März 2024 um 10:39 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/5 "2024-03-25T10:39:48Z")

</div>

Setz mal 0.0.0.0/0 als Trusted Proxy, wenn das dann klappt, dann hast du die falschen IPs hinterlegt.

---

<div class="post-metadata">

**Author:** ![MBDealer](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/mbdealer/32/27217_2.png) [@MBDealer](https://forum.shopware.com/u/MBDealer)\
**Post date:** [25. März 2024 um 10:44 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/6 "2024-03-25T10:44:00Z")

</div>

Deine Trusted Headers sind nur vom kopieren aus der Konsole abgeschnitten oder?

---

<div class="post-metadata">

**Author:** ![nets](https://avatars.discourse-cdn.com/v4/letter/n/c68b51/32.png) [@nets](https://forum.shopware.com/u/nets)\
**Post date:** [25. März 2024 um 11:31 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/7 "2024-03-25T11:31:03Z")

</div>

So sieht die .env aktuell aus

```auto
###> symfony/messenger ###
# Choose one of the transports below
# MESSENGER_TRANSPORT_DSN=amqp://guest:guest@localhost:5672/%2f/messages
# MESSENGER_TRANSPORT_DSN=redis://localhost:6379/messages
# doctrine://default?auto_setup=0
###< symfony/messenger ###

###> symfony/mailer ###
# MAILER_DSN=null://null
###< symfony/mailer ###

###> symfony/lock ###
# Choose one of the stores below
# postgresql+advisory://db_user:db_password@localhost/db_name
LOCK_DSN=flock
###< symfony/lock ###

TRUSTED_PROXIES=0.0.0.0/0
#TRUSTED_PROXIES=127.0.0.1,127.0.0.2,192.168.112.5,192.168.112.6,192.168.112.3,192.168.160.2
#TRUSTED_PROXIES=127.0.0.1,127.0.0.2,192.168.112.5,192.168.112.6,192.168.112.3
TRUSTED_HOSTS=vanill.at,www.vanill.at

###> shopware/core ###
APP_ENV=prod
APP_URL=http://127.0.0.1:8000
APP_SECRET=<redacted>
INSTANCE_ID=<redacted>
BLUE_GREEN_DEPLOYMENT=0
DATABASE_URL=mysql://root:root@localhost/shopware
# With Shopware 6.4.17.0 the MAILER_DSN variable will be used in this template instead of MAILER_URL
MAILER_URL=null://null
###< shopware/core ###

###> shopware/elasticsearch ###
OPENSEARCH_URL=http://localhost:9200
SHOPWARE_ES_ENABLED=0
SHOPWARE_ES_INDEXING_ENABLED=0
SHOPWARE_ES_INDEX_PREFIX=sw
SHOPWARE_ES_THROW_EXCEPTION=1
###< shopware/elasticsearch ###

###> shopware/storefront ###
STOREFRONT_PROXY_URL=http://localhost
SHOPWARE_HTTP_CACHE_ENABLED=1
SHOPWARE_HTTP_DEFAULT_TTL=7200
###< shopware/storefront ###

```

so sieht die `.env.local` aktuell aus

```auto
APP_SECRET=<redacted>
APP_URL=https://vanill.at
DATABASE_URL=mysql://<redacted>:<redacted>@lcmp-mysql-1:3306/shopwaredb
COMPOSER_HOME=/var/www/html/var/cache/composer
INSTANCE_ID=<redacted>
BLUE_GREEN_DEPLOYMENT=0
OPENSEARCH_URL=http://localhost:9200
ADMIN_OPENSEARCH_URL=http://localhost:9200
TRUSTED_PROXIES=0.0.0.0/0
TRUSTED_DOMAINS=vanill.at
TRUSTED_HEADERS='["x-forwarded-for", "x-forwarded-host", "x-forwarded-proto", "x-forwarded-port", "x-forwarded-prefix"]'

```

Ja, die waren wegen dem Kopieren abgeschnitten.

So sieht das Netzwerk `caddy` aus

```auto
[
    {
        "Name": "caddy",
        "Id": "51d3eb268905ce067549daae818be0e613f010a7313b89d60813b77c68ac6897",
        "Created": "2024-03-24T19:07:33.964517939+01:00",
        "Scope": "local",
        "Driver": "bridge",
        "EnableIPv6": false,
        "IPAM": {
            "Driver": "default",
            "Options": {},
            "Config": [
                {
                    "Subnet": "192.168.160.0/20",
                    "Gateway": "192.168.160.1"
                }
            ]
        },
        "Internal": false,
        "Attachable": false,
        "Ingress": false,
        "ConfigFrom": {
            "Network": ""
        },
        "ConfigOnly": false,
        "Containers": {
            "29c1ab73a8d0806796e4a44375d929ca0be19d5fa0d10f72fd8b173681b955fd": {
                "Name": "srv-caddy-1",
                "EndpointID": "d7085d73c9b5d24917c5b4a75e97d3d786ac3174421948547d635e64fb28c3ff",
                "MacAddress": "02:42:c0:a8:a0:02",
                "IPv4Address": "192.168.160.2/20",
                "IPv6Address": ""
            },
            "4e098bf3bb07a4e081e7281371fba6e2c9cc1c79513be9164dae32b068692e9f": {
                "Name": "lcmp-caddy-1",
                "EndpointID": "139cd0aed64eccf6635e2658fda9c6cacfd6e2c13586a88c302977e53df95b7e",
                "MacAddress": "02:42:c0:a8:a0:04",
                "IPv4Address": "192.168.160.4/20",
                "IPv6Address": ""
            },
            "db9f6bda393229a14613234285a1d32b12fd4c1909f8c4915de3579f82d54e77": {
                "Name": "lcmp-php-1",
                "EndpointID": "9e1069a4d869075cb73ddaea120d121fc88ab1803b6ff04e3e1dd71e41b1a2a3",
                "MacAddress": "02:42:c0:a8:a0:03",
                "IPv4Address": "192.168.160.3/20",
                "IPv6Address": ""
            }
        },
        "Options": {},
        "Labels": {}
    }
]

```

Das ist die interne IP-Adresse des Caddy proxies

```auto
docker container inspect 29c1ab73a8d0 | grep "IPAddress"
            "SecondaryIPAddresses": null,
            "IPAddress": "",
                    "IPAddress": "192.168.160.2",

```

Fehler unverändert

---

<div class="post-metadata">

**Author:** ![nets](https://avatars.discourse-cdn.com/v4/letter/n/c68b51/32.png) [@nets](https://forum.shopware.com/u/nets)\
**Post date:** [27. März 2024 um 15:14 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/8 "2024-03-27T15:14:05Z")

</div>

@MBDealer Herzlichen Dank für Deinen Tipp mit der` .env.local`, das war Teil der Lösung. Ich musste zusätzlich auch

```auto
php_fastcgi php:9000 {
	trusted_proxies private_ranges
}

```

im Caddyfile in `/srv/lcmp/caddy_docker` ändern, damit der PHP Service die Header korrekt weiterleitet

Schöne Grüße

---

<div class="post-metadata">

**Author:** ![nets](https://avatars.discourse-cdn.com/v4/letter/n/c68b51/32.png) [@nets](https://forum.shopware.com/u/nets)\
**Post date:** [10. April 2024 um 10:01 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/9 "2024-04-10T10:01:48Z")

</div>

Ich habe jetzt wieder den Fehler, dass Inhalte über http angefordert werden statt https, obwohl ich in der

```auto
# config/packages/framework.yaml
framework:
    # ...
    # the IP address (or range) of your proxy
    trusted_proxies: '0.0.0.0/0'
    # trust *all* "X-Forwarded-*" headers
    trusted_headers: ['x-forwarded-for', 'x-forwarded-host', 'x-forwarded-proto', 'x-forwarded-port', 'x-forwarded-prefix']
    # or, if your proxy instead uses the "Forwarded" header
    #trusted_headers: ['forwarded']

```

gesetzt habe und in der `.env.local`

```auto
APP_SECRET=<redacted>
APP_URL=https://shop3.vanill.at
DATABASE_URL=mysql://shopwaredbuser:<redacted>@lcmp-mysql-3:3306/shopwaredb
COMPOSER_HOME=/var/www/html/var/cache/composer
#INSTANCE_ID=<redacted>
BLUE_GREEN_DEPLOYMENT=0
OPENSEARCH_URL=http://localhost:9200
ADMIN_OPENSEARCH_URL=http://localhost:9200
TRUSTED_PROXIES=0.0.0.0/0
TRUSTED_DOMAINS=shop3.vanill.at
TRUSTED_HEADERS='["x-forwarded-for", "x-forwarded-host", "x-forwarded-proto", "x-forwarded-port", "x-forwarded-prefix"]'

```

sowie in der `.env`

```auto
###> shopware/core ###
APP_ENV=prod
APP_URL=https://127.0.0.1:8000
APP_SECRET=<redacted>
INSTANCE_ID=<redacted>
BLUE_GREEN_DEPLOYMENT=0
DATABASE_URL=mysql://root:root@localhost/shopware
# With Shopware 6.4.17.0 the MAILER_DSN variable will be used in this template instead of MAILER_URL
MAILER_URL=null://null
###< shopware/core ###

TRUSTED_PROXIES=0.0.0.0/0
TRUSTED_DOMAINS=shop3.vanill.at
TRUSTED_HEADERS='["x-forwarded-for", "x-forwarded-host", "x-forwarded-proto", "x-forwarded-port", "x-forwarded-prefix"]'

###> symfony/messenger ###
# Choose one of the transports below
# MESSENGER_TRANSPORT_DSN=amqp://guest:guest@localhost:5672/%2f/messages
# MESSENGER_TRANSPORT_DSN=redis://localhost:6379/messages
# doctrine://default?auto_setup=0
###< symfony/messenger ###

###> symfony/mailer ###
# MAILER_DSN=null://null
###< symfony/mailer ###

###> symfony/lock ###
# Choose one of the stores below
# postgresql+advisory://db_user:db_password@localhost/db_name
LOCK_DSN=flock
###< symfony/lock ###

###> shopware/elasticsearch ###
OPENSEARCH_URL=http://localhost:9200
SHOPWARE_ES_ENABLED=0
SHOPWARE_ES_INDEXING_ENABLED=0
SHOPWARE_ES_INDEX_PREFIX=sw
SHOPWARE_ES_THROW_EXCEPTION=1
###< shopware/elasticsearch ###

###> shopware/storefront ###
STOREFRONT_PROXY_URL=https://localhost
SHOPWARE_HTTP_CACHE_ENABLED=1
SHOPWARE_HTTP_DEFAULT_TTL=7200
###< shopware/storefront ###

```

So sieht das `Caddyfile` aus

```auto
:80 {
    encode gzip zstd
    root * /var/www/html/public
    php_fastcgi php-lcmp3:9000 {
        trusted_proxies private_ranges
    }
    file_server
    header {
        -server
        -Link
        -X-Powered-By

        # disable FLoC tracking
        #Permissions-Policy interest-cohort=()

        # enable HSTS
        Strict-Transport-Security max-age=31536000;

        # disable clients from sniffing the media type
        X-Content-Type-Options nosniff

        # clickjacking protection
        X-Frame-Options DENY

       # keep referrer data off of HTTP connections
       Referrer-Policy no-referrer-when-downgrade
    }

    log
}

```

Ich habe echt keine Ahnung mehr, woran das jetzt noch liegen könnte.

---

<div class="post-metadata">

**Author:** ![nets](https://avatars.discourse-cdn.com/v4/letter/n/c68b51/32.png) [@nets](https://forum.shopware.com/u/nets)\
**Post date:** [24. April 2024 um 09:33 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/10 "2024-04-24T09:33:29Z")

</div>

Ich konnte es lösen, in dem ich diese index.php verwendet habe

> <https://github.com/shopware/recipes/blob/main/shopware/core/6.4/public/index.php#L36-L47>

---

<div class="post-metadata">

**Author:** ![Hotte2](https://avatars.discourse-cdn.com/v4/letter/h/e56c9b/32.png) [@Hotte2](https://forum.shopware.com/u/Hotte2)\
**Post date:** [10. Juni 2024 um 14:45 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/11 "2024-06-10T14:45:18Z")

</div>

Gibt es eine Lösung / Erklärung wie das jetzt in den aktuellen Releases persistent gelöst wird ?

Mit [NEXT-29302 - Fix changelog and phpstan error · shopware/shopware@52258fe · GitHub](https://github.com/shopware/shopware/commit/52258fe369d85bb577eff9df29fb5ce2b7a84e66) wurde das verhalten scheinbar geändert…

Ich werde ja jetzt nicht nach jedem Update die Index aus Version 6.5.3 kopieren oder ?!? 😃  
Da muss doch etwas an der Konfiguration anders oder so ?? Oder ?

Benutzt keiner auf keiner aktuellen Version CloudFlare o.ä. ?

---

<div class="post-metadata">

**Author:** ![mj.es](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/mj.es/32/24133_2.png) [@mj.es](https://forum.shopware.com/u/mj.es)\
**Post date:** [5. Juli 2024 um 14:41 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/12 "2024-07-05T14:41:45Z")

</div>

Wenn du die Trusted Proxies in deiner .env oder .env.local definiert hast, genügt es [laut Symfony](https://symfony.com/doc/current/deployment/proxies.html#solution-settrustedproxies), in der z-framework.yaml die Trusted Proxies aus dem Environment zu übernehmen

```auto
# config/packages/z-framework.yaml
framework:
    # ...
    trusted_proxies: '%env(TRUSTED_PROXIES)%'

```

---

<div class="post-metadata">

**Author:** ![runi](https://avatars.discourse-cdn.com/v4/letter/r/f475e1/32.png) [@runi](https://forum.shopware.com/u/runi)\
**Post date:** [24. September 2024 um 08:46 UTC](https://forum.shopware.com/t/shopware-hinter-reverse-proxy-nutzt-http-statt-https/101323/13 "2024-09-24T08:46:52Z")

</div>

Vielen Dank, die Lösung mit der z-framework.yaml hat bei mir in Version 6.6.6.1 funktioniert.

> [@mj.es](#):
>
> ```auto
> # config/packages/z-framework.yaml
> framework:
> # ...
> trusted_proxies: '%env(TRUSTED_PROXIES)%'
> 
> ```

Ich hatte zwar die TRUSTED\_PROXIES Zeile in der .env.local und das hat auch bis Version 6.5.x funktioniert. Aber beim letzten Update auf die 6.6 Version hatte ich wieder das Problem mit http Links. Da wird die Variable wohl nicht mehr standardmäßig aus der .env.local ausgelesen.

Merci 👍
