Repository navigation
feat: add Forward Auth access policies #65
Copy link
Copy link
Closed
Labels
area: authAuthentication, accounts, sessions, passkeys, and access control.Authentication, accounts, sessions, passkeys, and access control.area: proxyProxy host configuration and request forwarding.Proxy host configuration and request forwarding.enhancementNew feature or requestNew feature or requestrelatedRelated work that is not a confirmed duplicate.Related work that is not a confirmed duplicate.securityPublic security hardening or remediation; disclose vulnerabilities privately.Public security hardening or remediation; disclose vulnerabilities privately.
Milestone
Description
No activity
Activity on this issue will appear here.
Activity
Metadata
Metadata
Assignees
Labels
area: authAuthentication, accounts, sessions, passkeys, and access control.Authentication, accounts, sessions, passkeys, and access control.area: proxyProxy host configuration and request forwarding.Proxy host configuration and request forwarding.enhancementNew feature or requestNew feature or requestrelatedRelated work that is not a confirmed duplicate.Related work that is not a confirmed duplicate.securityPublic security hardening or remediation; disclose vulnerabilities privately.Public security hardening or remediation; disclose vulnerabilities privately.
Summary
Extend RentnerProxy Access Policies with structured Forward Auth support on the
v1.0.0-alpha.6baseline.The feature should support compatible external authentication gateways such as Authentik,
Authelia, and oauth2-proxy without accepting arbitrary Caddy configuration.
Alpha 6 baseline
Preserve the current typed Access Policy model, server-side RBAC, strict trusted-proxy and
original-scheme handling, revision-checked runtime reconciliation, Basic Auth, IPv4/IPv6 rules,
WebSockets, HTTP/3, and certificate lifecycle behavior.
Goals
protocol semantics
Security
assumption
errors
Failure behavior
Define bounded timeouts and explicit behavior for unavailable auth services, invalid responses,
TLS failures, malformed headers, and runtime reload/restart. Requests must not hang or enter retry
loops.
UX
Provide clear Access Policy configuration and validation in the existing design system. Users
must not need to understand Caddy JSON.
Acceptance criteria
Priority and sequencing
P0 / major Beta feature. Builds on #28, #30, #31 and the completed Alpha 6 trust foundations.
Required for #75 unless explicitly deferred with rationale. Do not start as part of #64; begin
only after the CrowdSec implementation has been reviewed.