diff --git a/npm-config.conf b/npm-config.conf new file mode 100644 index 0000000..b581ee0 --- /dev/null +++ b/npm-config.conf @@ -0,0 +1,53 @@ +# Increase buffer size for large headers from Authentik +proxy_buffers 8 16k; +proxy_buffer_size 32k; + +# Exclude static assets from forward auth +# These paths bypass auth_request but still proxy to upstream +location ~ ^/(manifest\.json|favicon\.(ico|png)|health|icons|assets) { + auth_request off; + proxy_pass $forward_scheme://$server:$port; +} + +# Forward authentication via standalone outpost +auth_request /outpost.goauthentik.io/auth/nginx; +error_page 401 = @goauthentik_proxy_signin; + +# Capture auth response headers +auth_request_set $auth_cookie $upstream_http_set_cookie; +auth_request_set $authentik_username $upstream_http_x_authentik_username; +auth_request_set $authentik_groups $upstream_http_x_authentik_groups; +auth_request_set $authentik_email $upstream_http_x_authentik_email; +auth_request_set $authentik_name $upstream_http_x_authentik_name; +auth_request_set $authentik_uid $upstream_http_x_authentik_uid; + +# Forward auth headers to application +add_header Set-Cookie $auth_cookie; +proxy_set_header X-authentik-username $authentik_username; +proxy_set_header X-authentik-groups $authentik_groups; +proxy_set_header X-authentik-email $authentik_email; +proxy_set_header X-authentik-name $authentik_name; +proxy_set_header X-authentik-uid $authentik_uid; + +# Outpost proxy location +location /outpost.goauthentik.io { + proxy_pass https://localhost:9444/outpost.goauthentik.io; + proxy_set_header Host $host; + proxy_set_header X-Original-URL $scheme://$http_host$request_uri; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header X-Forwarded-Host $http_host; + proxy_set_header X-Forwarded-For $remote_addr; + proxy_pass_request_body off; + proxy_set_header Content-Length ""; + + # WebSocket support + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection $connection_upgrade; +} + +# Signin redirect handler +location @goauthentik_proxy_signin { + internal; + return 302 /outpost.goauthentik.io/start?rd=$request_uri; +} \ No newline at end of file