a month ago
My Railway service
UnClipIT-Musicis deployed successfully and marked Active.
/api/healthworks and returns HTTP 200:
{"status":"ok","service":"unclipit-music"}However, all HTML routes redirect to
/login, including/,/demo, and/loginitself. This createsERR_TOO_MANY_REDIRECTSin Chrome, Edge, and Incognito mode.The same application works locally:
/,/demo, and/loginall return HTTP 200 without redirects. The GitHub repository andmainbranch are connected correctly, and Railway build/deploy logs show Next.js starting successfully.Public domain:
unclipit-music-production.up.railway.appCould someone help check whether an external Railway routing, proxy, authentication, or domain redirect is causing this behavior?
2 Replies
a month ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • about 1 month ago
a month ago
This is most likely an issue with your middleware, where unauthenticated users are being redirected too many times in a cycle, and I assume you are authenticated on your local setup, that's why you don't see this error. If you can provide your middleware code, I can help you fix it.
a month ago
This looks like a middleware auth-check issue rather than a Railway routing problem — the signature (/api/health returns 200 fine, but every HTML route including /login itself redirects to /login) is the classic infinite-redirect pattern from an auth middleware.ts whose condition is either matching /login when it shouldn't, or never seeing a valid session in production.
Two things worth checking:
Your middleware matcher — if it's something like matcher: ['/((?!api|_next/static|favicon.ico).*)'], that still catches /login, so the auth check runs there too and loops forever. /login needs to be explicitly excluded.
If you're using NextAuth/Auth.js: check that NEXTAUTH_URL (or AUTH_URL in v5) and AUTH_TRUST_HOST=true are set as env vars on Railway, matching your exact public domain. Locally this defaults to localhost and works fine; in production behind Railway's proxy, a missing/mismatched URL can make session/cookie validation silently fail on every request — so the app thinks you're always logged out, even on /login.
Works locally + fails only in production + hits every route is a strong signal it's env-config, not code.