Skip to content

feat: add Forward Auth access policies #65

Description

@RentnerKev

Summary

Extend RentnerProxy Access Policies with structured Forward Auth support on the
v1.0.0-alpha.6 baseline.

The feature should support compatible external authentication gateways such as Authentik,
Authelia, and oauth2-proxy without accepting arbitrary Caddy configuration.

Alpha 6 baseline

Preserve the current typed Access Policy model, server-side RBAC, strict trusted-proxy and
original-scheme handling, revision-checked runtime reconciliation, Basic Auth, IPv4/IPv6 rules,
WebSockets, HTTP/3, and certificate lifecycle behavior.

Goals

  • structured Forward Auth configuration in the existing Access Policy model
  • validated upstream URL and safe transport options
  • explicit request-header and auth-response-header allowlists
  • clear timeout and failure behavior
  • correct Proxy Host integration
  • defined ordering/combination with Basic Auth and IP rules
  • compatible flows for Authentik, Authelia, oauth2-proxy, and other services with matching
    protocol semantics

Security

  • validate schemes, hosts, ports, redirects, and TLS behavior
  • prevent unsafe request/response header forwarding and credential leakage
  • do not create an open redirect
  • keep SSRF limited to an explicit administrator-controlled auth endpoint and document the trust
    assumption
  • derive the original scheme/client context only from the Alpha 6 trusted-proxy contract
  • keep server-side authorization authoritative; hidden UI actions are not access control
  • encrypt any persisted secret and redact it from browser responses, logs, audit metadata, and
    errors

Failure behavior

Define bounded timeouts and explicit behavior for unavailable auth services, invalid responses,
TLS failures, malformed headers, and runtime reload/restart. Requests must not hang or enter retry
loops.

UX

Provide clear Access Policy configuration and validation in the existing design system. Users
must not need to understand Caddy JSON.

Acceptance criteria

  • Authentik-compatible flow works.
  • Authelia-compatible flow works where protocol semantics match.
  • Successful auth forwards the intended identity headers only.
  • Failed, malformed, or unavailable auth blocks or degrades according to documented policy.
  • Header, redirect, SSRF, secret, and trusted-scheme behavior are covered by tests.
  • Basic Auth and IP rules retain their current semantics.
  • Real Caddy runtime tests and production smokes pass.
  • Required documentation and final security review security: complete v1 beta security review #72 include the shipped behavior.

Priority and sequencing

P0 / major Beta feature. Builds on #28, #30, #31 and the completed Alpha 6 trust foundations.
Required for #75 unless explicitly deferred with rationale. Do not start as part of #64; begin
only after the CrowdSec implementation has been reviewed.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, accounts, sessions, passkeys, and access control.area: proxyProxy host configuration and request forwarding.enhancementNew feature or requestrelatedRelated work that is not a confirmed duplicate.securityPublic security hardening or remediation; disclose vulnerabilities privately.

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions