Skip to content

[FEATURE] Non-label based access control #356

Description

@MitPitt

Is your feature request related to a problem? Please describe.

Access controls and other per-app features are seemingly only available via docker labels. But some of the apps I host are not docker containers, and some are on other machines. This makes it impossible to set up custom access control for them.

Describe the solution you'd like

There must be a way to do this without docker labels. Access control features should be set up in tinyauth's own config only. Perhaps a sensible solution is creating profiles. They would be used via their uri path.

Example profiles.json:

"profiles":
[
    "/": {},
    "/librechat": {"users": "user1", "allowed": "^\/api"}
]

After mounting profiles.json in tinyauth it would let me use these profiles in caddyfile:

(tinyauth_forwarder) {
        forward_auth 127.0.0.1:3789 {
                uri /api/auth/caddy
        }
}

(tinyauth_forwarder_librechat) {
        forward_auth 127.0.0.1:3789 {
                uri /librechat/api/auth/caddy
        }
}

whoami.example.com{
        import tinyauth_forwarder
        reverse_proxy 127.0.0.1:3000
}

librechat.example.com{
        import tinyauth_forwarder_librechat
        reverse_proxy 10.11.12.5:3000
}

Activity

  1. steveiliop56 commented on Sep 13, 2025

    @steveiliop56
    Member

    Hello,

    While this would solve the issue it would break the project's base idea, (quoted from the documentation):

    I am planning to keep the app in this state while slowly adding QOL updates. I am not planning to add any fancy dashboards or configuration files since I do not want to change the project's base idea.

    One way to configure ACLs would be with environment variables/CLI flags (e.g. ACLS_FOO_CONFIG_DOMAIN) but I am not very sure if it would be that user friendly.

  2. rinseaid commented on Sep 26, 2025

    @rinseaid

    I would also love to see a similar feature - using TinyAuth to protect all my apps is my goal. I'd be ok with environment variables/CLI flags, since it would eliminate having to create an external configuration file - I don't think it's too alien a concept for users who would be needing such a feature.

  3. raghuscsa316 commented on Oct 9, 2025

    @raghuscsa316

    +1
    Would also love the ability for Tinyauth to support authentication to different apps based on profiles/groups.

  4. pantherman594 commented on Oct 10, 2025

    @pantherman594

    I'm also using the binary, not docker, and would appreciate a way to configure access controls without docker labels.

    but I am not very sure if it would be that user friendly

    I would also be ok with configuring with environment variables/CLI flags, and there's already a precedence for it with the multiple OAuth providers feature you recently added for v4.

  5. purple-emily commented on Oct 14, 2025

    @purple-emily

    I don't use docker labels or caddy-docker-proxy. I use normal Caddy with a Caddyfile and I am wanting to allow a n8n instance to perform an API call on another service that is protected by TinyAuth. I am not sure how to allow this and can't find anything in the documentation to help.

  6. chrellrich commented on Oct 15, 2025

    @chrellrich
    Contributor

    This would be a great feature allowing for more varied usecases. Might I ask why you are against using a config file? I think if done in a similar fashion to traefik (where you can enable a file provider) it would be pretty intuitive.

  7. steveiliop56 commented on Oct 15, 2025

    @steveiliop56
    Member

    Alright, let's add a simple yaml config file for storing ACLs. I will mark this issue as pinned so as it won't be closed by the stale bot.

  8. steveiliop56 commented on Oct 21, 2025

    @steveiliop56
    Member

    Added in #422! You will be able to use TINYAUTH_APPS_WHATEVER_FOO=BAR to configure ACLs using environment variables (and hopefully CLI flags)!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or requestpinnedThis issue is pinned

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions