Running a Blog on the Same Domain as Your AT Protocol PDS

By Saeed Al Falasi (@falasi.net)
Published:

If you self-host an AT Protocol PDS and want to run a blog like GreenGale on the same parent domain, you've probably hit this error:

Forbidden sec-fetch-site header "same-site"

This happens because the AT Protocol OAuth provider only allows cross-site and none for the Sec-Fetch-Site header. When your blog and PDS share the same parent domain (e.g. md.falasi.net and bsky.falasi.net), the browser correctly sends same-site — and the PDS rejects it.

The Fix

Credit to mary-ext for identifying this fix upstream.

Find this file inside your PDS container:

node_modules/@atproto/oauth-provider/dist/router/create-authorization-page-middleware.js

Locate this line:

validateFetchSite(req, ['same-origin', 'cross-site', 'none']);

And change it to:

validateFetchSite(req, ['same-origin', 'same-site', 'cross-site', 'none']);

Then restart your PDS. That's it — OAuth will now work across subdomains of the same parent domain.

Making It Stick

This change will be overwritten whenever you update your PDS. Remember to re-apply the patch after each update until it lands officially upstream.

A proper fix is being tracked in the atproto repo — bluesky-social/atproto#4131.