1
[Feature Request] add crossorigin="use-credentials" to manifest link - Web manifest blocked behind auth proxies –
Source: paperless-ngx/paperless-ngx#14302 · opened by @haweffo-spec
Description
When Paperless-ngx runs behind an authenticating reverse proxy such as Cloudflare Access, the browser console shows a CORS error for /static/frontend/<lang>/manifest.webmanifest.
Cause: browsers fetch the web app manifest without cookies unless the link tag says otherwise. The proxy sees an unauthenticated request, redirects it to its login page on another domain, and the browser blocks that redirect.
Suggested fix in src/documents/templates/index.html:
This has no effect on setups without a proxy. Other projects made the same change for the same reason, e.g. Dashy ( and Open WebUI (
When Paperless-ngx runs behind an authenticating reverse proxy such as Cloudflare Access, the browser console shows a CORS error for /static/frontend/<lang>/manifest.webmanifest.
Cause: browsers fetch the web app manifest without cookies unless the link tag says otherwise. The proxy sees an unauthenticated request, redirects it to its login page on another domain, and the browser blocks that redirect.
Suggested fix in src/documents/templates/index.html:
This has no effect on setups without a proxy. Other projects made the same change for the same reason, e.g. Dashy ( and Open WebUI (
No pledges yet. Be the first to back this.
Comments
Similar requests
[Feature Request] Optional WebSocket heartbeat to keep status connections alive behind reverse proxies / CDNs
1 vote · 0 comments
[Feature Request] Check for duplicates after running a pre consume script
5 votes · 0 comments
[Feature Request] Add security-relevant logging for authentication and document share links
3 votes · 0 comments
[Feature Request] Option to export "notes" as TXT files next to the PDF in document_exporter
3 votes · 0 comments
[Feature Request] Support ETSI ASiC-E signed documents (EU e-signed docs)
2 votes · 0 comments
No comments yet.