Skip to content

[FEATURE] Subpaths Support. #313

Description

@gatodelcaribe

Is your feature request related to a problem? Please describe.
Need to request Auth to certain paths, it's easy to do it with sub-domains due Caddy reverse proxy request but sub-path is very complex if TinyAuth doesn't allow it by default.

Describe the solution you'd like
I would like to make Tinyauth work for certain URL like mydomain.com/private, mydomain.com/testing. And mydomain.com/open being available to open access to everyone without pass to TinyAuth.

Describe alternatives you've considered
Used Authentik proxy but really want only use one auth app for now.

Activity

  1. steveiliop56 commented on Aug 14, 2025

    @steveiliop56
    Member

    Sure why not. Do you have an idea of how this could be implemented label wise? How would you like to configure such access controls?

  2. gatodelcaribe commented on Aug 18, 2025

    @gatodelcaribe
    Author

    Using the allowing path formula there can be a rule where auth only work on these sub paths, like this but inverse? tinyauth.allowed: ^\/subpath

    We can think about skipping authentication for specific paths, that this path is "Black Listed" and every other single path is. "White listed" for verification.

    If we can have a label that respond on "This exact path / word need verification" will solve a bit the problem

  3. steveiliop56 commented on Aug 18, 2025

    @steveiliop56
    Member

    Hmm why wouldn't this work with the allowed label? For example Tinyauth can be enabled for all endpoints except your open one.

  4. gatodelcaribe commented on Aug 20, 2025

    @gatodelcaribe
    Author

    "Tinyauth also supports skipping authentication for specific paths. This can be useful if you need an API path to be accessed without needing to login to Tinyauth."

    If i have multiple paths on a website like /blog /private /status /x /y /z

    With the Allowed Label workflow, I need as you said to enable it for all endpoints except your open one.

    On my needs, I need the opposite. Just an only sub path being behind the auth but not the entire Domain for example. Maybe I want to share private 2 sub paths.

  5. steveiliop56 commented on Aug 20, 2025

    @steveiliop56
    Member

    Ohh got it so the allowed paths but reverse. Alright will try to implement it in v4.

  6. added a commit that references this issue on Aug 29, 2025
    26deb80
  7. added a commit that references this issue on Aug 29, 2025
    c7c3de4
  8. steveiliop56 commented on Aug 29, 2025

    @steveiliop56
    Member

    Added in #329. You will be able to do:

    tinyauth.apps.my-app.path.block: some-regex

    Which will allow all paths except the ones matching the regex.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions