This release includes breaking changes for platform teams planning a safe upgrade.
Published 2mo
Reverse Proxies & Load Balancers
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
alpine-linux
bcrypt
crsf
csrf-protection
docker
fernet
+13 more
flask
flask-limiter
flask-session
gunicorn
phosphor-icons
python
ruamel-yaml
tailwind-css
totp
traefik
traefik-management
traefik-web-ui
vanilla-js
Affected surfaces
auth
breaking_upgrade
Summary
AI summaryFixed Authelia forward‑auth template to use the current endpoint and ensured OIDC callback URLs honor X‑Forwarded‑Proto for HTTPS.
Full changelog
Bug Fixes
- Authelia forward-auth template uses deprecated endpoint - the built-in Authelia middleware template was using the legacy
/api/verify?rd=...URL. Updated to/api/authz/forward-authto match current Authelia documentation. (#39) - OIDC callback URL uses http instead of https behind reverse proxy - TM now respects
X-Forwarded-Protofrom Traefik so OIDC redirect URIs correctly usehttpswhen running behind a TLS-terminating reverse proxy. (#40)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]