From a6fc9daab994a6f1ad52ca195da530c41e147126 Mon Sep 17 00:00:00 2001 From: Jeroen Schweitzer Date: Sun, 4 Jan 2026 19:19:31 +0100 Subject: [PATCH] docs: add NPM forward auth config for reference MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Config for home.schweitz.net with Authentik forward auth: - Static assets excluded via auth_request off - Proper proxy pass to upstream 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 --- npm-config.conf | 53 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 53 insertions(+) create mode 100644 npm-config.conf diff --git a/npm-config.conf b/npm-config.conf new file mode 100644 index 0000000..b581ee0 --- /dev/null +++ b/npm-config.conf @@ -0,0 +1,53 @@ +# Increase buffer size for large headers from Authentik +proxy_buffers 8 16k; +proxy_buffer_size 32k; + +# Exclude static assets from forward auth +# These paths bypass auth_request but still proxy to upstream +location ~ ^/(manifest\.json|favicon\.(ico|png)|health|icons|assets) { + auth_request off; + proxy_pass $forward_scheme://$server:$port; +} + +# Forward authentication via standalone outpost +auth_request /outpost.goauthentik.io/auth/nginx; +error_page 401 = @goauthentik_proxy_signin; + +# Capture auth response headers +auth_request_set $auth_cookie $upstream_http_set_cookie; +auth_request_set $authentik_username $upstream_http_x_authentik_username; +auth_request_set $authentik_groups $upstream_http_x_authentik_groups; +auth_request_set $authentik_email $upstream_http_x_authentik_email; +auth_request_set $authentik_name $upstream_http_x_authentik_name; +auth_request_set $authentik_uid $upstream_http_x_authentik_uid; + +# Forward auth headers to application +add_header Set-Cookie $auth_cookie; +proxy_set_header X-authentik-username $authentik_username; +proxy_set_header X-authentik-groups $authentik_groups; +proxy_set_header X-authentik-email $authentik_email; +proxy_set_header X-authentik-name $authentik_name; +proxy_set_header X-authentik-uid $authentik_uid; + +# Outpost proxy location +location /outpost.goauthentik.io { + proxy_pass https://localhost:9444/outpost.goauthentik.io; + proxy_set_header Host $host; + proxy_set_header X-Original-URL $scheme://$http_host$request_uri; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header X-Forwarded-Host $http_host; + proxy_set_header X-Forwarded-For $remote_addr; + proxy_pass_request_body off; + proxy_set_header Content-Length ""; + + # WebSocket support + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection $connection_upgrade; +} + +# Signin redirect handler +location @goauthentik_proxy_signin { + internal; + return 302 /outpost.goauthentik.io/start?rd=$request_uri; +} \ No newline at end of file