diff --git a/Caddyfile b/Caddyfile index f43f9df..e018b0d 100644 --- a/Caddyfile +++ b/Caddyfile @@ -39,16 +39,9 @@ media.hubris.network { tls { dns ionos {env.IONOS_AUTH_API_TOKEN} } - # API and streaming paths — no Authentik (Jellyfin apps use their own auth) - @api path /api/* /socket /Audio/* /Videos/* /Items/* /Users/* /Sessions/* /System/* /LiveTv/* /Music/* /Artists/* /Albums/* /Playlists/* /Images/* /Subtitle* /videos/* /audio/* /sso/* /SSO-Auth/* - handle @api { - reverse_proxy 192.168.8.206:8096 - } - # Web UI — gated behind Authentik - handle { - import authentik - reverse_proxy 192.168.8.206:8096 - } + # SSO plugin handles auth via OIDC redirect to Authentik. + # No forward-auth gate — Jellyfin login page shows SSO button directly. + reverse_proxy 192.168.8.206:8096 } git.hubris.network {