Skip to content

fix: support login through SSO reverse proxies in the WebView - #282

Open
andig wants to merge 4 commits into
mainfrom
fix/external-auth-proxy
Open

andig wants to merge 4 commits into
mainfrom
fix/external-auth-proxy

Conversation

@andig

@andig andig commented Sep 10, 2026

Copy link
Copy Markdown
Member

fixes #35, fixes #140

evcc behind an auth proxy (oauth2-proxy, Authentik, Authelia, Cloudflare Access) could not be added: the server check hit the proxy's login page instead of evcc, and the WebView kicked the identity provider's login page out to the system browser, where the session cookie never reached the WebView. This adds an explicit opt-in per server so the strict compatibility check stays in place for everyone else.

  • New "Login via reverse proxy" toggle in the server form. With it on, the check only requires the address to be reachable; a login page (302 to another origin, 401/403 or a same-host form) is accepted and the entered URL is saved as-is.
  • For such servers the WebView keeps cross-origin navigations in-app until the evcc UI reports online, so the whole SSO round trip (proxy → IdP → callback → evcc) runs in one cookie jar. Afterwards foreign links open externally as before.
  • The login page is shown instead of the loading overlay, and 401/403 no longer trigger the offline/remount loop for these servers. The evcc UI reports online by itself once the login went through; an expired session simply lands on the login page again after the next reload.
  • Caddyfile gains a fake auth proxy (:7090) plus identity provider on a separate origin (:7091); a Detox test logs in through it inside the WebView on both platforms.

Scope and known limits:

  • Google as identity provider refuses sign-in from embedded WebViews (disallowed_useragent). GitHub, email/OTP, Keycloak, Authentik/Authelia local accounts work. Not fixable app-side without a token handoff the proxy would have to support.
  • Widgets keep using basic auth only; SSO-protected servers stay unsupported there.
  • Deep links (evcc://server?…) do not prefill the toggle yet.

andig and others added 2 commits September 10, 2026 09:40
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@andig
andig requested a review from naltatis September 10, 2026 07:44
andig and others added 2 commits September 10, 2026 09:57
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…the button

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

reverse proxy mit Authentifizierung via Google/Github etc... Authentication on iOS redirects to browser

1 participant