Auto-login from trusted reverse-proxy Authentik headers
When SSO_GATEWAY_SECRET is set and an incoming request carries both X-Artifacto-Gateway (matching the secret) and X-Authentik-Username, the admin middleware mints a session automatically so Authentik-authenticated users skip the password form. Missing or wrong gateway header falls back to the password-login flow, so peers that can reach the container directly (bypassing the reverse proxy) cannot spoof Authentik identities.
This commit is contained in:
@@ -10,6 +10,7 @@ services:
|
||||
SESSION_SECRET: ${SESSION_SECRET:?set in .env}
|
||||
BASE_URL: ${BASE_URL:-https://artifacto.hubris.network}
|
||||
MAX_UPLOAD_MB: ${MAX_UPLOAD_MB:-5}
|
||||
SSO_GATEWAY_SECRET: ${SSO_GATEWAY_SECRET:-}
|
||||
volumes:
|
||||
- ./data:/data
|
||||
ports:
|
||||
|
||||
Reference in New Issue
Block a user