Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Feature Requests
  3. Extra Auth

Extra Auth

Scheduled Pinned Locked Moved Feature Requests
loginsso
5 Posts 3 Posters 593 Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      D Offline
      dimtar
      wrote on last edited by joseph
      #1

      Hi all.

      I’ve spent some time reading but either I can’t find the feature or it simply doesn’t exist.
      I understand that Cloudron has a user system and can act as an SSO provider with apps that support it.

      What I am wondering is, is there a way to add an extra auth step? For example like Authentik or Authelia where you must authenticate before you even see the app.

      For example say I installed Immich and then enabled this feature, I would need to login/auth before I even saw the Immich login page?

      Is this possible/available?

      1 Reply Last reply
      1
      • J Online
        J Online
        joseph
        Staff
        wrote on last edited by
        #2

        @dimtar we don't have this feature, no. With your setup, does one login twice? Once in Authentik/Authelia and then into Immich ?

        1 Reply Last reply
        2
        • J joseph moved this topic from Support on
        • D Offline
          D Offline
          dimtar
          wrote on last edited by
          #3

          I don't have that setup currently but it's what I am looking for.
          I feel that opening services like Immich to the web would be more secure if they had an extra step.

          1 Reply Last reply
          0
          • fbartelsF Offline
            fbartelsF Offline
            fbartels
            App Dev
            wrote on last edited by
            #4

            Cloudron kind of has this functionality, but it is only used in Apps that otherwise would not have authentication at all: https://docs.cloudron.io/packaging/addons/#proxyauth

            @joseph said in Extra Auth:

            With your setup, does one login twice? Once in Authentik/Authelia and then into Immich ?

            Some applications can make use of such an external auth and recognize which user should be logged in. For others you would need to login twice. Similarly if the application you put behind such a wall has e.g. an Android app then also this app needs to know how to pass the "extra auth".

            J 1 Reply Last reply
            1
            • fbartelsF fbartels

              Cloudron kind of has this functionality, but it is only used in Apps that otherwise would not have authentication at all: https://docs.cloudron.io/packaging/addons/#proxyauth

              @joseph said in Extra Auth:

              With your setup, does one login twice? Once in Authentik/Authelia and then into Immich ?

              Some applications can make use of such an external auth and recognize which user should be logged in. For others you would need to login twice. Similarly if the application you put behind such a wall has e.g. an Android app then also this app needs to know how to pass the "extra auth".

              J Online
              J Online
              joseph
              Staff
              wrote on last edited by
              #5

              @fbartels said in Extra Auth:

              Android app then also this app needs to know how to pass the "extra auth".

              Good point! In all likelihood it will break APIs

              1 Reply Last reply
              0
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


                • Login

                • Don't have an account? Register

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • Bookmarks
                • Search