Repository navigation
Feature/reverse proxy web auth - #997
Meganitrospeed wants to merge 26 commits into
Conversation
|
Thank you very much for your contribution! I think if this works for you I will simply merge it and other users can then request improvements if required. |
|
Any feedback so far? |
|
Hi, I'm now working on a complete rewrite for the Grocy app with modern best practices because this project uses many deprecated dependencies and technologies and is just too messy to further maintain. I hope you understand and I will try to implement your approach in the new project. |
Is the new repo public ? Can I contribute in some form? |
|
No sadly not, it's still in early development but I try my best to get things done fast in my (not that much) free time. |


Summary
This PR adds support for Grocy instances protected by an interactive reverse proxy, such as Authentik.
Currently, when Grocy Android checks
/api/system/info, the reverse proxy can return its HTML login page instead of the expected Grocy JSON response. The app then displays “Target is not a Grocy instance.”My Grocy installation uses the following configuration:
Changes
HttpURLConnection.GROCY-API-KEYheader for Grocy API authentication.This does not implement OAuth/OIDC directly. The WebView establishes the reverse proxy’s existing browser session, after which the app continues using the normal Grocy API.
Security considerations
X-Authentik-Username; the trusted reverse proxy remains responsible for injecting that header.Automated tests
Unit tests were added for:
Testing performed
I tested the implementation with an Authentik-protected Grocy installation using the reverse-proxy middleware configuration shown above.
Additional testing of other identity providers and reverse-proxy configurations would be appreciated.