Config is DB-backed (metadata.app_config) — there is no config.json — so the reverse-proxy settings I added earlier had NO way to be set by a user and were effectively dead. Added them to Settings → Security, next to the launch-PIN toggle: - "Behind a reverse proxy" checkbox (security.trust_reverse_proxy) — help text notes it's for nginx/Caddy/Traefik+TLS, to leave OFF for direct/LAN http://, and that it needs a restart (applied at app init). - "Auth proxy user header" field (security.auth_proxy_header) — e.g. Remote-User, with the must-strip-client-headers warning; blank = off. Wired into the existing settings load + save; the save loop already persists every key in the security object via config_manager.set, so no backend change needed. Fixed Support/REVERSE-PROXY.md to point at Settings → Security instead of a nonexistent config.json. Off by default → zero impact for direct users. 64 script-split integrity tests pass. |
||
|---|---|---|
| .. | ||
| API.md | ||
| AUTOMATIONS.md | ||
| DOCKER-OAUTH-FIX.md | ||
| DOCKER-TRANSFER-GUIDE.md | ||
| DOCKER.md | ||
| DOCKER_PERMISSIONS.md | ||
| IMPORT-STAGING-GUIDE.md | ||
| METADATA-FALLBACK-IMPLEMENTATION.md | ||
| README-Docker.md | ||
| REVERSE-PROXY.md | ||
| UNRAID.md | ||