Self-Hosted: SSO broken when using Authentik

(#597) Bug Fixed self-hosting

Summary

When trying to use SSO to sign in with Authentik as the provider, Fluxer fails to login with the SSO user. Logs show a status code 400 when failing the login.

Steps to reproduce

  1. Install Fluxer
  2. In Authentik create Application and Provider with Strick redirect to https://chat.example.com/auth/sso/callback
  3. In Fluxer go to https://chat.example.com/admin/instance-config and fill out the SSO section.
Display Name: Authentik Issuer: https://auth.example.com/application/o/fluxer/ Authorization URL: https://auth.example.com/application/o/authorize/ Token URL: https://auth.example.com/application/o/token/ User Info URL: https://auth.example.com/application/o/userinfo/ JWKS URL: https://auth.example.com/application/o/fluxer/jwks/ Client ID: <Client ID from Authentik> Client Secret: <Client Secret from Authentik> Scope: openid email profile
  1. Save settings and try to login with SSO

Environment

Version: 149.0.7827.103 (Official Build) (64-bit) OS: Ubuntu Server 26.04

Logs or screenshots

api-1               | {"level":"info","time":"2026-06-16T18:02:50.757Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":3,"msg":"Request completed"}
app-proxy-1         | 2026-06-16T18:02:50.757980Z  INFO fluxer_app_proxy::discovery_cache: discovery cache updated url="http://caddy:8088/api/.well-known/fluxer" api_code_version=unknown
api-1               | {"level":"info","time":"2026-06-16T18:02:52.449Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/complete","status":400,"durationMs":1131,"msg":"Request completed"}
worker-1            | {"level":"info","time":"2026-06-16T18:02:55.678Z","service":"fluxer-api","env":"production","workerId":"worker-batch-c124b7a9-67a4-4aaa-a1c3-1747e2641bad","lane":"batch","taskType":"syncUrlBlocklists","seq":1313,"redelivered":true,"msg":"Processing job"}

12 comments

Sign in with Fluxer to comment and vote.
Comment by @Nome200
RexSystem 1 vote originally by @Nome200 on GitHub
I'm also getting the 400 in the logs. After the api service logs a status 400 the admin service logs this:
admin-1             | 2026-06-16T21:36:43.802074Z  WARN fluxer_admin::routes::system_actions: admin API request failed: update instance config error=HTTP 400: {"code":"INVALID_FORM_BODY","message":"Invalid form body.","errors":[{"path":"issuer","message":"Invalid URL format.","code":"INVALID_URL_FORMAT"}]}
This happens regardless of what the URL actually looks like. https://auth.example.com/application/o/fluxer-test, https://auth.example.com and auth.example.com/application/o/fluxer-test don't work. The message in the admin panel when saving could also print out the error instead of a green "Done.", but that's another issue.
Comment by @TheUncleDolan
RexSystem 1 vote originally by @TheUncleDolan on GitHub
Would fluxer resolve your auth endpoint to an IP part of a reserved local range?
Comment by @Hudeler
RexSystem 1 vote originally by @Hudeler on GitHub
It looks like the URL validation does not like subdomains for the URL in the "Issuer" field. E.g. https://example.com/ works as expected but https://idp.example.com/ causes the INVALID_FORM_BODY/INVALID_URL_FORMAT error and the config does not persist.
Comment by @nadd3r
RexSystem 1 vote originally by @nadd3r on GitHub OP
It looks like the URL validation does not like subdomains for the URL in the "Issuer" field. E.g. https://example.com/ works as expected but https://idp.example.com/ causes the INVALID_FORM_BODY/INVALID_URL_FORMAT error and the config does not persist.
Try including the application in the url. For Authentik I have https://auth.example.com/application/o/fluxer/ and everything saves but then fails silently with the 400 in the logs.
Comment by @Buco7854
RexSystem 1 vote originally by @Buco7854 on GitHub
Would fluxer resolve your auth endpoint to an IP part of a reserved local range?
Clarifying: For anyone having the same issue. If your IdP resolves to a private IP fluxer will not allow it and those codes are the one being thrown iirc. To circumvent it try adding dns directive to your api service and set any public dns, you can also use extra_hosts to force resolving to your public IP instead. I dont think there is anyway to configure that behavior so for now I suppose having a public IP for your provider is required.
Comment by @nadd3r
RexSystem 1 vote originally by @nadd3r on GitHub OP
> Would fluxer resolve your auth endpoint to an IP part of a reserved local range? Clarifying: For anyone having the same issue. If your IdP resolves to a private IP fluxer will not allow it and those codes are the one being thrown iirc. To circumvent it try adding dns directive to your api service and set any public dns, you can also use extra_hosts to force resolving to your public IP instead. I dont think there is anyway to configure that behavior so for now I suppose having a public IP for your provider is required.
My Authentik instance is exposed to the internet via a Cloudflare tunnel. The Ubuntu Server Fluxer is running on has 1.1.1.1 and 1.0.0.1 set as the DNS servers and resolves Authentik to the public IP of the Cloudflare tunnel.
Comment by @Buco7854
RexSystem 1 vote originally by @Buco7854 on GitHub
Seems its something else then. You sure you didn't miss something else in logs ? Also did you try forging a request yourself to authentik to see what it would answer from fluxer's container. Edit: Forgot to mention it but I have Authentik (2026.5.3) Also check that the field email_verified is set to true in authentik response (you can previsialize it in Provider settings) If no either create a Property Mapping or set the field true for you users.
Comment by @nadd3r
RexSystem 1 vote originally by @nadd3r on GitHub OP
Seems its something else then. You sure you didn't miss something else in logs ? Also did you try forging a request yourself to authentik to see what it would answer from fluxer's container. Edit: Forgot to mention it but I have Authentik (2026.5.3) Also check that the field email_verified is set to true in authentik response (you can previsialize it in Provider settings) If no either create a Property Mapping or set the field true for you users.
I was originally running Authentik 2025.12.4 and have since updated to 2026.5.3. Looking at the logs from the Fluxer API container I can still see the following logs when trying to login with SSO:
api-1  | {"level":"info","time":"2026-06-17T16:59:51.138Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/start","status":200,"durationMs":7,"msg":"Request completed"}
api-1  | {"level":"info","time":"2026-06-17T16:59:51.547Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":6,"msg":"Request completed"}
api-1  | {"level":"info","time":"2026-06-17T16:59:53.345Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/complete","status":400,"durationMs":1192,"msg":"Request completed"}
However, if I go into Authentik and create a Property Mapping with the following information: Mapping Name: email_verified_true Scope Name: email Expression: return { "email": request.user.email, "email_verified": True } Then go into the Fluxer Provider and under Scopes swap out authentik default OAuth Mapping: OpenID 'email' with the created email_verified_true then try to login to Fluxer via SSO I can see the following in the Fluxer API logs:
api-1  | {"level":"info","time":"2026-06-17T17:03:16.503Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/start","status":200,"durationMs":6,"msg":"Request completed"}
api-1  | {"level":"info","time":"2026-06-17T17:03:16.894Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":7,"msg":"Request completed"}
api-1  | {"level":"info","time":"2026-06-17T17:03:18.708Z","service":"fluxer-api","env":"production","logger":"SsoService","email":"user@example.com","has_sub":true,"msg":"SSO login with sub claim"}
api-1  | {"level":"info","time":"2026-06-17T17:03:18.715Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/complete","status":403,"durationMs":1231,"msg":"Request completed"}
I didn't see anything in the Authentik logs other than the typical authorization of the application. If there are any other logs I can provide to help troubleshoot this issue then please let me know what I should include or where to look.
Comment by @Buco7854
RexSystem 1 vote originally by @Buco7854 on GitHub
When I had those 2 issue I mentioned, I had some uppercase code in the logs for the first one and second was kind of explicit iirc. What is surprising is your log doesn't show much I honestly don't know. Your property mapping is right tho.
Comment by @nadd3r
RexSystem 1 vote originally by @nadd3r on GitHub OP
I'll include the logs from my Authentik server just in case they are helpful.
1781719900437	2026-06-17T18:11:40.437Z	{"auth_via": "oauth_token", "domain_url": "auth.example.com", "event": "/application/o/userinfo/", "host": "auth.example.com", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 162, "remote": "172.16.3.15", "request_id": "6b4a66ebfdb04844a1d280f7dd74bac3", "runtime": 71, "schema_name": "public", "scheme": "https", "status": 200, "timestamp": "2026-06-17T18:11:40.436796", "user": "", "user_agent": "fluxer-api"}

1781719900279	2026-06-17T18:11:40.279Z	{"auth_via": "unauthenticated", "domain_url": "auth.example.com", "event": "/application/o/fluxer/jwks/", "host": "auth.example.com", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 162, "remote": "172.16.3.15", "request_id": "f580c74147464bc8a18a8dd8b98e5d42", "runtime": 318, "schema_name": "public", "scheme": "https", "status": 200, "timestamp": "2026-06-17T18:11:40.279137", "user": "", "user_agent": "fluxer-api"}

1781719899868	2026-06-17T18:11:39.868Z	{"auth_via": "oauth_client_secret", "domain_url": "auth.example.com", "event": "/application/o/token/", "host": "auth.example.com", "level": "info", "logger": "authentik.asgi", "method": "POST", "pid": 162, "remote": "172.16.3.15", "request_id": "e6f92a40b66a4b41a075abd1ab0a3feb", "runtime": 382, "schema_name": "public", "scheme": "https", "status": 200, "timestamp": "2026-06-17T18:11:39.867812", "user": "", "user_agent": "fluxer-api"}

1781719898741	2026-06-17T18:11:38.741Z	{"auth_via": "session", "domain_url": "auth.example.com", "event": "/application/o/authorize/?response_type=code&client_id=OAUTH_CLIENT_ID&redirect_uri=https%3A%2F%2Fchat.example.com%2Fauth%2Fsso%2Fcallback&scope=openid+email+profile&state=ff4a07eeac962375c6cee705704a6a92&code_challenge=tx8bjP80VsyNGTpbpIVBgll3lHxklniDDgO3wgil2OM&code_challenge_method=S256&nonce=VYLhdWEJBKBr5pyZ18jn7A", "host": "auth.example.com", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 162, "remote": "192.168.2.146", "request_id": "94bced33057b4df792e198548ef671d6", "runtime": 301, "schema_name": "public", "scheme": "https", "status": 302, "timestamp": "2026-06-17T18:11:38.740851", "user": "fluxer-user", "user_agent": "Mozilla/5.0 (X11; Linux x86_64; rv:151.0) Gecko/20100101 Firefox/151.0"}

1781719898659	2026-06-17T18:11:38.659Z	{"auth_via": "session", "domain_url": "auth.example.com", "event": "Task enqueued", "host": "auth.example.com", "level": "info", "logger": "authentik.tasks.middleware", "pid": 162, "request_id": "94bced33057b4df792e198548ef671d6", "schema_name": "public", "task_id": "76b2e739-4954-4ea1-bba5-98e9fae20c1b", "task_name": "authentik.events.tasks.event_trigger_dispatch", "timestamp": "2026-06-17T18:11:38.659116"}

1781719898613	2026-06-17T18:11:38.613Z	{"action": "authorize_application", "auth_via": "session", "client_ip": "192.168.2.146", "context": {"authorized_application": {"app": "authentik_core", "model_name": "application", "name": "Fluxer", "pk": "9d77b13bb2d34922a5d51e7d7f0744af"}, "flow": "5c5db42f14f14354a6625bc74aee276a", "http_request": {"args": {"client_id": "OAUTH_CLIENT_ID", "code_challenge": "tx8bjP80VsyNGTpbpIVBgll3lHxklniDDgO3wgil2OM", "code_challenge_method": "S256", "nonce": "VYLhdWEJBKBr5pyZ18jn7A", "redirect_uri": "https://chat.example.com/auth/sso/callback", "response_type": "code", "scope": "openid email profile", "state": "ff4a07eeac962375c6cee705704a6a92"}, "method": "GET", "path": "/application/o/authorize/", "request_id": "94bced33057b4df792e198548ef671d6", "user_agent": "Mozilla/5.0 (X11; Linux x86_64; rv:151.0) Gecko/20100101 Firefox/151.0"}, "scopes": "email profile openid"}, "domain_url": "auth.example.com", "event": "Created Event", "host": "auth.example.com", "level": "info", "logger": "authentik.events.models", "pid": 162, "request_id": "94bced33057b4df792e198548ef671d6", "schema_name": "public", "timestamp": "2026-06-17T18:11:38.613462", "user": {"email": "user@example.com", "pk": 6, "username": "fluxer-user"}}

1781719886687	2026-06-17T18:11:26.687Z	{"auth_via": "oauth_token", "domain_url": "auth.example.com", "event": "/application/o/userinfo/", "host": "auth.example.com", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 160, "remote": "172.16.3.1", "request_id": "1616f43069f6434b9f3d731cd71403a3", "runtime": 86, "schema_name": "public", "scheme": "https", "status": 200, "timestamp": "2026-06-17T18:11:26.687531", "user": "", "user_agent": "Go-http-client/1.1"}
I do notice the unauthenticated for the path `/application/o/fluxer/jwks/ so that may be the culprit here but I am not sure.
Comment by @Buco7854
RexSystem 1 vote originally by @Buco7854 on GitHub
When you try the "user path". Like go to login page try to connect with SSO etc... what happens now? can you send a screenshot etc of what it displays? Just to make sure wére on the same page and we fix one issue after the other. But tbf I think thats an issue on your side and not a fluxer one
Comment by @nadd3r
RexSystem 1 vote originally by @nadd3r on GitHub OP
When you try the "user path". Like go to login page try to connect with SSO etc... what happens now? can you send a screenshot etc of what it displays? Just to make sure wére on the same page and we fix one issue after the other. But tbf I think thats an issue on your side and not a fluxer one
This issue appeared to be on my side. When I tried to get the screenshots of the error everything just worked as expected. If the issue crops up again I'll reopen this ticket but for now the issue appears to be resolved by updating Authentik.