Skip to content

Protect Paperless with Authelia forward auth#83

Merged
sidey79 merged 2 commits into
mainfrom
feat/paperless-authelia-sso
Apr 14, 2026
Merged

Protect Paperless with Authelia forward auth#83
sidey79 merged 2 commits into
mainfrom
feat/paperless-authelia-sso

Conversation

@sidey79

@sidey79 sidey79 commented Apr 12, 2026

Copy link
Copy Markdown
Owner

Summary

  • switch the dms vhost from mTLS-only access to Authelia forward_auth
  • forward Authelia identity headers upstream so Paperless can use HTTP_REMOTE_USER
  • document the Paperless authentication path in the repo README

Validation

  • docker compose -f docker-compose.yml config
  • caddy validate --config caddy/Caddyfile currently fails on an unrelated pre-existing matcher in the workflow block (header X-Telegram-Bot-Api-Secret-Token {$TELEGRAM_WEBHOOK_SECRET})

Notes

  • the dms upstream remains paperless-ngx-webserver-1.network_backend_net:8000
  • Authelia remains the enforced login path for Paperless

@sidey79
sidey79 marked this pull request as ready for review April 14, 2026 06:35
@sidey79
sidey79 merged commit ce20d7b into main Apr 14, 2026
2 checks passed
@sidey79
sidey79 deleted the feat/paperless-authelia-sso branch April 14, 2026 06:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant