Skip to content

fix(l4): public authlevel also need set ext_auth - #3956

Merged
eball merged 2 commits into
mainfrom
module-l4-bfl-proxy
Aug 14, 2026
Merged

fix(l4): public authlevel also need set ext_auth#3956
eball merged 2 commits into
mainfrom
module-l4-bfl-proxy

Conversation

@hysyeah

@hysyeah hysyeah commented Aug 14, 2026

Copy link
Copy Markdown
Member
  • Background
    fix(l4): public authlevel also need set ext_auth

  • Target Version for Merge
    v1.12.7

  • Related Issues
    None

  • PRs Involving Sub-Systems
    None

  • Other information:


Note

Medium Risk
Changes north-south auth for all entrances labeled public and touches Authelia header forwarding on the edge proxy; misconfiguration could block previously anonymous endpoints or affect token-based flows until apps are adjusted.

Overview
Bumps l4-bfl-proxy to v0.3.46 in the Olares upgrade path, BFL launcher env (L4_PROXY_IMAGE_VERSION), and prebuilt image manifest.

Routing / auth behavior: App default and custom-domain catch-all routes no longer skip Authelia when authLevel is public—they always set ExtAuth via buildAppExtAuthConfig, and the isPublicAuthLevel helper is removed. Signed webhook probe paths still bypass auth on their dedicated routes.

Envoy xDS: Authelia ext_authz now allows authorization and proxy-authorization on upstream responses from the auth check (in addition to existing remote- / authelia- prefixes), so credential-related headers can flow correctly through the verify path.

Reviewed by Cursor Bugbot for commit 994fe2a. Bugbot is set up for automated code reviews on this repo. Configure here.

@vercel

vercel Bot commented Aug 14, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
olares-docs Ignored Ignored Aug 14, 2026 1:50pm

Request Review

@eball
eball merged commit 84feb0b into main Aug 14, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants