Files
ubuntu-post-install/services
Claude 9aacb17a4d Pin X-Forwarded-Host on the Authelia portal's own Caddy block
The generated auth.<domain> block's bare "reverse_proxy authelia:9091"
let Caddy recompute X-Forwarded-Host from its own incoming request
(always auth.<domain> itself) on every hop through it, overwriting
whatever a forward_auth caller elsewhere had already set for its own
domain. Confirmed live: a remote site's forward_auth check always
evaluated as if it were for the Authelia portal itself (bypass policy),
so 2FA silently never triggered for any domain going through it.
2026-07-20 22:31:07 +00:00
..