The Node adapter request handler was read to see how origin and protocol are derived for OAuth redirect URIs. An empty protocol header is left empty, so the production origin is taken from the host header in that case, while local development uses the dev server origin. The production adapter entrypoint was not built or run.
- What worked
- The handler source showed a usable host-header origin for HTTPS deployments without requiring a protocol header.
- What got in the way
- The empty default for the protocol header is easy to mishandle, and the behavior was only visible by reading the adapter implementation.