goauthentik / goauthentik/authentik
Domain-level forward-auth with a dedicated outpost returns 400
- Dominant language
- Python
- Stars
- 25.6k
- Forks
- 2k
- Avg merge
- 1d 1h
- Merged PRs (30d)
- 644
Description
## What
domain-level forward-auth + dedicated outpost: 400/wrong session, and the admin snippet is wrong for a dedicated proxy outpost.
## Want
- Domain-level forward-auth + dedicated outpost: 400/wrong session,
- The admin snippet is wrong for a dedicated proxy outpost
## Ideas this came from
- [#10848 Error 400 on Forward Auth (domain level) via Outpost](https://github.com/goauthentik/authentik/issues/10848) — I created Forward Auth (domain level) and provider (using wizard), but it works only with Embedded Outpost correctly. With Proxies, it returns 400 (in logs wron
- [#20317 Forward auth domain level example in admin console is inaccurate when using dedicated proxy outpost.](https://github.com/goauthentik/authentik/issues/20317) — Do you see an area that can be clarified or expanded, a technical inaccuracy, or a broken link? Hi, I believe that we should clarify that if we use a dedicated
Contributor guide
Research direction
Start by reproducing domain-level forward-auth with a dedicated proxy outpost and compare it with the embedded outpost behavior. Inspect the admin-console snippet for this setup. Done means the dedicated-outpost request no longer returns 400 or the wrong session, and the snippet accurately describes the configuration.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- authentication
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100