#Forward auth (single app) only asks for authentication one time.

1 messages · Page 1 of 1 (latest)

void flame
#

Hello!, I have my first proxy provider enabled, the first time you go to the site xyz.domain.com it asks for auth. I have the token validity set for 1 hour. However it never expires and the session remains active on the browser infinitely. Where should I start looking?

void flame
#

Still havent figured this out.

boreal coral
#

Try closing the browser and reopening. I have experienced the same issue but found that, or what I think it is, the browser holding the session until it gets a "hard" refresh, but not entirely sure why this happens. I have mine set to 24 hours but i can stay logged into any apps for about a week before authentik asks for new authentication, and at times this can happen even after a pc restart but not authentik server restart. I mostly use Firefox as my browser, but I have noticed that when I use Brave, it tends to work better.

void flame
#

So this is intended for users other than myself. So while I can probably MAKE it reauth my sessions, I want it to reauth anyone who visits the site after 1 hour

boreal coral
#

I understand. I have the same issue, but not really too worried about it since all my users are people I know. I know this has been an issue with Authentik for a while now and has been brought up multiple times. I'm not sure if it is Authentik or if it is the Browser causing this. I'm not that good at digging into logs or anything else like that to figure things like this out, so I do process of elimination the best I can by testing other browsers or using a VM to test, or by doing whatever else I can, however I can.

void flame
#

Yeah iI have tried multiple browsers and locations. Unfortionately it seems to follow.

prisma escarp
#

Are you sure it isn't just invisibly redirecting you to authentik, seeing you're logged in there, and this allowing you to be immediately forwarded back to the application?

void flame
#

Yes, I can visit the site in question after having only visited it once before on the same browser. It will pass me directly into the site without credentials.
Then I can in the same browser window, go direct to auth.domain.com and be asked for credentials to login.

fresh heath
#

I also have the same problem, the token expiration date is set to 7 hours, this time is ignored. The cookie properties are set permanently to 1 month. I reinstalled different versions of the program several times, the problem remains. I don’t see a solution to this problem, as if I am alone with it.

prisma escarp
#

That's interesting, because with single app forward auth with nginx I am every so often required to authenticate again to open the apps