goauthentik / goauthentik/authentik

Domain-level forward-auth with a dedicated outpost returns 400

Open
#25,317 0 comments 1 reaction 0 assignees View on GitHub
area:docs bug enhancement/confirmed
Dominant language
Python
Stars
25.6k
Forks
2k
Avg merge
1d 1h
Merged PRs (30d)
644

Description

## What

domain-level forward-auth + dedicated outpost: 400/wrong session, and the admin snippet is wrong for a dedicated proxy outpost.

## Want

- Domain-level forward-auth + dedicated outpost: 400/wrong session,
- The admin snippet is wrong for a dedicated proxy outpost

## Ideas this came from

- [#10848 Error 400 on Forward Auth (domain level) via Outpost](https://github.com/goauthentik/authentik/issues/10848) — I created Forward Auth (domain level) and provider (using wizard), but it works only with Embedded Outpost correctly. With Proxies, it returns 400 (in logs wron
- [#20317 Forward auth domain level example in admin console is inaccurate when using dedicated proxy outpost.](https://github.com/goauthentik/authentik/issues/20317) — Do you see an area that can be clarified or expanded, a technical inaccuracy, or a broken link? Hi, I believe that we should clarify that if we use a dedicated

Contributor guide

Open the contributing guide

Research direction

Start by reproducing domain-level forward-auth with a dedicated proxy outpost and compare it with the embedded outpost behavior. Inspect the admin-console snippet for this setup. Done means the dedicated-outpost request no longer returns 400 or the wrong session, and the snippet accurately describes the configuration.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
authentication
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.