diff --git a/apps/base/arrstack/arrproxy/oauth2-proxy-configmap.yaml b/apps/base/arrstack/arrproxy/oauth2-proxy-configmap.yaml index e850f40..a7eee62 100644 --- a/apps/base/arrstack/arrproxy/oauth2-proxy-configmap.yaml +++ b/apps/base/arrstack/arrproxy/oauth2-proxy-configmap.yaml @@ -37,6 +37,11 @@ data: # /sonarr/api but NOT /api/tokens or /api/me (which stay authenticated). OAUTH2_PROXY_SKIP_AUTH_REGEX: "^/[^/]+/api" OAUTH2_PROXY_EMAIL_DOMAINS: "*" + # Authentik hardcodes email_verified=false in the id_token; without this + # oauth2-proxy rejects the session ("email ... isn't verified") -> 500 on + # /oauth2/callback. Authorization is enforced downstream via ak_groups, so + # accepting the unverified email here is safe. + OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true" OAUTH2_PROXY_COOKIE_SECURE: "true" OAUTH2_PROXY_COOKIE_DOMAINS: "arrstack.unkin.net" OAUTH2_PROXY_WHITELIST_DOMAINS: "arrstack.unkin.net"