Auto-login from trusted reverse-proxy Authentik headers

When SSO_GATEWAY_SECRET is set and an incoming request carries both
X-Artifacto-Gateway (matching the secret) and X-Authentik-Username, the
admin middleware mints a session automatically so Authentik-authenticated
users skip the password form. Missing or wrong gateway header falls back
to the password-login flow, so peers that can reach the container
directly (bypassing the reverse proxy) cannot spoof Authentik identities.
This commit is contained in:
claudio
2026-04-22 22:21:20 +02:00
parent c7d7ee287c
commit e74439b509
6 changed files with 63 additions and 16 deletions

View File

@@ -33,6 +33,7 @@ Then put a reverse proxy (Caddy, nginx, Traefik) in front for HTTPS.
| `BIND_ADDR` | `:3000` | Listen address |
| `MAX_UPLOAD_MB` | `5` | Per-artifact upload cap |
| `LOG_LEVEL` | `info` | `info` or `debug` |
| `SSO_GATEWAY_SECRET` | — | Optional: enables auto-login from a trusted reverse proxy forwarding Authentik headers plus a matching `X-Artifacto-Gateway` header |
## License