diff --git a/README.md b/README.md index f9b222d..971207f 100644 --- a/README.md +++ b/README.md @@ -15,3 +15,4 @@ Instead, a special service - `authelia-config` runs before authelia start, and p ## Lessons learned - Authelia will ONLY work with https. Both the authelia url itself and the one being authenticated must be https. +- The authorization link should NOT end with `/#/` or `/%2F/` or anything, just `/`. Otherwise it will not redirect you back after authorizing. diff --git a/traefik/config/security.yaml b/traefik/config/security.yaml index 4d7fffb..4903f78 100644 --- a/traefik/config/security.yaml +++ b/traefik/config/security.yaml @@ -27,9 +27,10 @@ http: auth: # Go through authelia for authorization forwardAuth: - address: http://authelia:9091/api/verify?rd=https://auth.{{ env "PRIVATE_DOMAIN" }}/%23/ + address: http://authelia:9091/api/verify?rd=https://auth.{{ env "PRIVATE_DOMAIN" }}/ trustForwardHeader: true authResponseHeaders: - X-Forwarded-User - insecureSkipVerify: true + tls: + insecureSkipVerify: true