goauthentik / goauthentik/authentik

HSTS support

Open
#8,640 3 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Python
Stars
25.6k
Forks
2k
Avg merge
1d 1h
Merged PRs (30d)
644

Description

**Is your feature request related to a problem? Please describe.**
I don't use authentik through reverse proxy, as it adds some extra complication, and it was easier to run it in a VM with its own IP. However, I no longer have control over HTTP vs HTTPS with this method. I would like to enforce HTTPS and disalow unencrypted traffic over standard HTTP, as it is less secure, but I haven't found a way to do so.

**Describe the solution you'd like**
The most user-friendly way could be a toggle in each Tennant/Brand to enforce HSTS. It could also be an environment variable set to `True`.

**Describe alternatives you've considered**
I could run authentik behind a reverse proxy again, which would allow for HSTS enforcement. However, as mentioned earlier, that requires more configuration than I am willing to do, especially since I use Nginx Proxy Manager instead of raw Nginx config files. Custom parameters are supported, but direct connections are far more simple.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.