goauthentik / authentik

The authentication glue you need.
https://goauthentik.io
Other
13.38k stars 892 forks source link

ForwardAuth forwarding to random file/URL #4093

Open tomlawesome opened 1 year ago

tomlawesome commented 1 year ago

Describe the bug

  1. Navigate to a subdomain protected by Authentik forward auth
  2. Click 'continue' (already signed in)
  3. Get forwarded to something random, not always related to the correct subdomain

To Reproduce Steps to reproduce the behavior: I am unsure how to repeat this bug because I don't know what's causing it.

Expected behavior

  1. Navigate to a subdomain protected by Authentik forward auth
  2. Click 'continue' (already signed in)
  3. Get forwarded to the subdomain correctly.

Screenshots In this case, I am forwarded to a random image asset that belongs to the site protected by Authentik: image

In another case, rather than forwarding to the site behind, this random file is downloaded: image

In a different case, I was forwarded to a totally different subdomain to the one I requested.

This only happens with Authentik.

Logs I would be happy to share logs, but would prefer to do so privately as I am unsure which parts are sensitive (codes, tokens etc).

Version and Deployment (please complete the following information):

Additional context This has only recently become a problem (last two updates or so). I am also having issues with JWT tokens with Guacamole and wonder if there is some link.

tomlawesome commented 1 year ago

Have updated to the latest release, 2022.11.2 and the issue persists.

RoboMagus commented 1 year ago

I've had similar issues for a number of months. I always figured it would have something to do with multiple simultaneous queries...

stale[bot] commented 1 year ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

Kaaybi commented 1 year ago

Having this issue as well on various applications (homeassistant, codeserver, dozzle, etc). It comes back on a daily-basis so feel free to ask for any logs!

dunxiii commented 8 months ago

Get the same problem on authentik 2023.10.7 and homepage.