Skip to content

Commit e9c63f0

Browse files
committed
fix: simplify guides for nginx and swag
1 parent 4f53c3c commit e9c63f0

2 files changed

Lines changed: 31 additions & 77 deletions

File tree

‎src/content/docs/docs/guides/nginx-proxy-manager.mdx‎

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -76,7 +76,7 @@ SSL can be configured as needed.
7676
7777
Add the following configuration in the Advanced tab to enable Tinyauth authentication:
7878
79-
```sh
79+
```nginx
8080
# Root location
8181
location / {
8282
# Pass the request to the app
@@ -105,9 +105,8 @@ location /tinyauth {
105105
# Pass the request headers
106106
proxy_set_header x-forwarded-for $remote_addr;
107107
proxy_set_header x-real-ip $remote_addr;
108-
proxy_set_header x-forwarded-proto $scheme;
109-
proxy_set_header x-forwarded-host $http_host;
110-
proxy_set_header x-forwarded-uri $request_uri;
108+
proxy_set_header x-original-url $scheme://$http_host$request_uri;
109+
proxy_set_header x-original-method $request_method;
111110
}
112111
```
113112

‎src/content/docs/docs/guides/swag.mdx‎

Lines changed: 28 additions & 73 deletions
Original file line numberDiff line numberDiff line change
@@ -5,78 +5,48 @@ description: Use Tinyauth with the LinuxServer.io SWAG reverse proxy.
55

66
[SWAG](https://docs.linuxserver.io/general/swag/) is an Nginx-based reverse proxy maintained by LinuxServer.io. Its proxy configuration samples include support for Tinyauth.
77

8-
:::caution[Temporary guide]
9-
This guide is temporary. The configuration below follows our open [SWAG pull request](https://github.com/linuxserver/docker-swag/pull/621), which adds support for Tinyauth's `X-Tinyauth-Location` header. We are waiting for LinuxServer.io to merge and release the pull request. Until then, the required configuration must be added manually.
10-
:::
11-
128
## Prerequisites
139

1410
- Tinyauth v5.2.0 or newer.
1511
- A working SWAG installation.
1612
- SWAG and Tinyauth attached to the same user-defined Docker network.
17-
- A Tinyauth container named `tinyauth`. If it has a different name, update `$upstream_tinyauth` below.
1813
- A proxy configuration for Tinyauth enabled by renaming `/config/nginx/proxy-confs/tinyauth.subdomain.conf.sample` to `/config/nginx/proxy-confs/tinyauth.subdomain.conf`.
1914

20-
## Configure Tinyauth Authentication
21-
22-
### Create the Tinyauth Proxy Configuration
23-
24-
:::caution[Required for Tinyauth v5.2.0 and newer]
25-
Tinyauth v5.2.0 and newer does not allow a request to contain both `X-Forwarded-Host` and `X-Forwarded-Uri` headers alongside `X-Original-URL`. SWAG's standard `/config/nginx/proxy.conf` sets all three headers, so a separate proxy configuration that clears the conflicting headers is required for Tinyauth authentication requests.
26-
:::
27-
28-
Create `/config/nginx/tinyauth-proxy.conf` with the following contents:
29-
30-
```nginx title="/config/nginx/tinyauth-proxy.conf"
31-
# Timeout if the upstream server is unavailable.
32-
proxy_next_upstream error timeout invalid_header http_500 http_502 http_503;
33-
34-
# Proxy connection settings.
35-
proxy_buffers 32 4k;
36-
proxy_connect_timeout 240;
37-
proxy_headers_hash_bucket_size 128;
38-
proxy_headers_hash_max_size 1024;
39-
proxy_http_version 1.1;
40-
proxy_read_timeout 240;
41-
proxy_redirect http:// $scheme://;
42-
proxy_send_timeout 240;
43-
44-
# Proxy cache and cookie settings.
45-
proxy_cache_bypass $cookie_session;
46-
proxy_no_cache $cookie_session;
47-
48-
# Proxy header settings.
49-
proxy_set_header Connection $connection_upgrade;
50-
proxy_set_header Early-Data $ssl_early_data;
51-
proxy_set_header Host $host;
52-
proxy_set_header Proxy "";
53-
proxy_set_header Upgrade $http_upgrade;
54-
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
55-
proxy_set_header X-Forwarded-Host "";
56-
proxy_set_header X-Forwarded-Uri "";
57-
proxy_set_header X-Forwarded-Method $request_method;
58-
proxy_set_header X-Forwarded-Port $server_port;
59-
proxy_set_header X-Forwarded-Proto $scheme;
60-
proxy_set_header X-Forwarded-Server $host;
61-
proxy_set_header X-Forwarded-Ssl on;
62-
proxy_set_header X-Original-Method $request_method;
63-
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
64-
proxy_set_header X-Real-IP $remote_addr;
65-
```
15+
## Tinyauth SWAG Configuration
16+
17+
### Server Configuration
18+
19+
Ensure your `/config/nginx/tinyauth-server.conf` file looks like this:
20+
21+
```nginx title="/config/nginx/tinyauth-server.conf"
22+
location /tinyauth {
23+
internal;
24+
25+
include /config/nginx/resolver.conf;
26+
# Replace this if your Tinyauth container has a different name
27+
set $upstream_tinyauth tinyauth;
28+
proxy_pass http://$upstream_tinyauth:3000/api/auth/nginx;
29+
30+
# Don't send the body to the auth server
31+
proxy_pass_request_body off;
32+
proxy_set_header Content-Length "";
6633
67-
Do not replace SWAG's standard `/config/nginx/proxy.conf` with this file. The custom file is only used by the Tinyauth authentication location.
34+
# Headers needed for authentication
35+
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
36+
proxy_set_header X-Original-Method $request_method;
37+
proxy_set_header X-Real-IP $remote_addr;
38+
}
39+
```
6840

69-
### Configure the Authentication Locations
41+
### Authentication Location
7042

71-
Replace the contents of `/config/nginx/tinyauth-location.conf` with:
43+
Ensure your `/config/nginx/tinyauth-location.conf` file looks like this:
7244

7345
```nginx title="/config/nginx/tinyauth-location.conf"
74-
# Send a subrequest to Tinyauth to verify the request.
7546
auth_request /tinyauth;
76-
auth_request_set $tinyauth_location $upstream_http_x_tinyauth_location;
77-
error_page 401 403 =302 $tinyauth_location;
47+
auth_request_set $redirection_url $upstream_http_x_tinyauth_location;
48+
error_page 401 403 =302 $redirection_url;
7849
79-
# Copy user information from the auth response to the protected app.
8050
auth_request_set $email $upstream_http_remote_email;
8151
auth_request_set $groups $upstream_http_remote_groups;
8252
auth_request_set $name $upstream_http_remote_name;
@@ -88,21 +58,6 @@ proxy_set_header Remote-Name $name;
8858
proxy_set_header Remote-User $user;
8959
```
9060

91-
Replace the contents of `/config/nginx/tinyauth-server.conf` with:
92-
93-
```nginx title="/config/nginx/tinyauth-server.conf"
94-
location /tinyauth {
95-
internal;
96-
97-
include /config/nginx/tinyauth-proxy.conf;
98-
include /config/nginx/resolver.conf;
99-
set $upstream_tinyauth tinyauth;
100-
proxy_pass http://$upstream_tinyauth:3000/api/auth/nginx;
101-
proxy_pass_request_body off;
102-
proxy_set_header Content-Length "";
103-
}
104-
```
105-
10661
This allows Tinyauth to choose the correct login, unauthorized, or error page and return it through the `X-Tinyauth-Location` response header.
10762

10863
## Protect an Application

0 commit comments

Comments
 (0)