goauthentik / goauthentik/authentik

Customizable stage failure, permission-denied, and policy-error text

Open
#25,249 0 comments 0 reactions 0 assignees View on GitHub
enhancement enhancement/confirmed
Dominant language
Python
Stars
25.6k
Forks
2k
Avg merge
1d 1h
Merged PRs (30d)
644

Description

## What

let admins customize the user-visible failure / permission-denied / “Failed to authenticate.” / policy-error text on stages. Also: stage-failure UX: customizable failure *messages* vs configurable failure *modes* (redirect/skip).

## Want

- Let admins customize the user-visible failure / permission-denied / “Failed to authenticate.” / policy-error text on stages
- Related stage-failure UX: customizable failure *messages* vs configurable failure *modes* (redirect/skip)
- Not the same control

_Review; not the same control._

## Ideas this came from

- [#8368 How to change the `Failed to authenticate.` text in login screen](https://github.com/goauthentik/authentik/issues/8368) — image Is it possible to customize the Failed to authenticate. text in login screen
- [#8964 How to show a custom permission denied message ?](https://github.com/goauthentik/authentik/issues/8964) — Sometimes users try to access an application which is blocked for them by an expression policy. It would be really helpful if I could show them a custom message
- [#9918 How to configure error messages / screen for password policy](https://github.com/goauthentik/authentik/issues/9918) — Describe your question/ I added the Password Policy to the "default-password-change" flow. 1. I don´t know how to configure some message about the password rule
- [#24076 Customizable failure messages on all applicable stage bindings](https://github.com/goauthentik/authentik/issues/24076) — e.g., Allow admins to set a custom message that is shown when an mTLS or Webauthn stage fails/doesn't pass
- [#24128 Allow admins to set failure modes on stages](https://github.com/goauthentik/authentik/issues/24128) — If a stage fails, such as a source or webauthn stage, allow admin to set what happens. For example, if a source stage fails, redirect the user to another flow/s

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are named. Start by reviewing stage failure handling and the linked issues (#8368, #8964, #9918, #24076, and #24128); done means a settled scope that distinguishes customizable messages from configurable failure modes and covers the listed errors.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.