Declined
1
Support reverse-proxy trusted header authentication (SSO behind Authelia / Authentik / oauth2-proxy)
Source: immich-app/immich#31364 · opened by @vincenttisseront
I have searched the existing feature requests, both open and closed, to make sure this is not a duplicate request. • Yes The feature Description Many Immich deployments sit behind a reverse proxy that already authenticates users (Authelia, Authentik, oauth2-proxy, Keycloak gate, Cloudflare Access, etc.). In that setup, the proxy injects identity headers on every request (for example X-Forwarded-Email, Remote-User, or configurable equivalents). Today Immich only offers password login and its own OIDC client. Even when the user is already authenticated at the proxy, Immich still shows its login page and requires a second authentication (local password or a full Immich→IdP OAuth round-trip). This is a common “SSO at the edge” pattern used by many self-hosted apps (e.g. Open WebUI’s WEBUI_AUTH_TRUSTED_* headers). We would like Immich to optionally trust those proxy headers and map them to an Immich user session without a second interactive login. Why this matters 1. …
No pledges yet. Be the first to back this.
Comments
Similar requests
Mobile App (Android) OAuth Auto Launch Not Working
0 votes · 0 comments
[Feature] Trusted Local Provisioning for Immich
1 vote · 0 comments
[Feature] Handle error and error_description more gracefully with denied via an Authorization Policy
1 vote · 0 comments
OAuth immich_quota claim does not updates user quota on login
0 votes · 0 comments
[Feature] Localized OAuth button
1 vote · 0 comments
No comments yet.