Non standard https port; CSP blocks resource at base domain. #4958
Unanswered
Gandalf-the-Blue
asked this question in
Q&A
Replies: 3 comments 2 replies
-
I'm using authelia v4.37.5 My conf files are as below -
My proxy.conf file is
|
Beta Was this translation helpful? Give feedback.
0 replies
-
To me it looks like your proxy is adjusting the content-security-policy and content-type headers. |
Beta Was this translation helpful? Give feedback.
0 replies
-
Hi @james-d-elliott , |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi,
I'm trying to run authelia on a non-standard https port @ https://authelia.example.tld:600. I'm using the latest docker image with swag as a reverse proxy. I am able to log in to the authelia portal with username and password and when the notification is sent to the file, it does not include the port in the url, which if I fix by hand before navigating to the url, nothing loads and the inspector shows this -
Content Security Policy: The page’s settings blocked the loading of a resource at https://authelia.example.tld/ (“base-uri”).
Loading module from “https://authelia.example.tld:600/one-time-password/static/js/index.fad9e36b.js” was blocked because of a disallowed MIME type (“text/html”).
Loading failed for the module with source “https://authelia.example.tld:600/one-time-password/static/js/index.fad9e36b.js”.
The resource from “https://authelia.example.tld:600/one-time-password/static/css/index.40feef90.css” was blocked due to MIME type (“text/html”) mismatch (X-Content-Type-Options: nosniff).
The first error "Content Security Policy: The page’s settings blocked the loading of a resource at https://authelia.example.tld/ (“base-uri”). " is also present when logging in via first factor but everything still seems to work.
I read through previous question - #2765 - but this maintains that the issue is resolved.
What am I missing here?
Beta Was this translation helpful? Give feedback.
All reactions