Self-hosted: SSO is failing to setup due to 400 from admin

(#603) Bug Fixed self-hosting

Summary

When I attempt to add my SSO provider with "Enable SSO" checkbox set, the settings do not persist, and SSO is not enabled.

Steps to reproduce

  1. Go to SSO settings
  2. Attempt to add an SSO provider, fill out all the correct URLs
  3. Set "Enable SSO" checkbox to enabled
  4. Click save

Environment

Latest v1 in Docker

Logs or screenshots

api-1               | {"level":"info","time":"2026-06-16T20:34:54.392Z","service":"fluxer-api","env":"production","method":"GET","path":"/admin/users/me","status":200,"durationMs":6,"msg":"Request completed"}
api-1               | {"level":"info","time":"2026-06-16T20:34:54.414Z","service":"fluxer-api","env":"production","method":"POST","path":"/admin/instance-config/update","status":400,"durationMs":6,"msg":"Request completed"}
admin-1             | 2026-06-16T20:34:54.415859Z  WARN fluxer_admin::routes::system_actions: admin API request failed: update instance config error=HTTP 400: {"code":"INVALID_FORM_BODY","message":"Invalid form body.","errors":[{"path":"issuer","message":"Invalid URL format.","code":"INVALID_URL_FORMAT"}]}

4 comments

Sign in with Fluxer to comment and vote.
Comment by @frenzeldk
RexSystem 1 vote edited originally by @frenzeldk on GitHub
@kerichdev it is not at all obvious, but your issuer host name has to resolve to a public IP. If your IDP is reachable through a public IP you can achieve this by adding the following to your docker-compose.yml file:
⋮
api:
  extra_hosts:
    - "idp.example.com:<PUBLIC_IP>"
Comment by @kerichdev
RexSystem 1 vote originally by @kerichdev on GitHub OP
Thanks! I'll try it out. Are you, by chance, aware if there are other funky caveats with non-public IPs? My whole setup sits behind OpenWRT so pretty much every domain resolves to a local IP.
Comment by @kerichdev
RexSystem 1 vote originally by @kerichdev on GitHub OP
Tip: this has essentially been resolved by manually specifying extra hosts, so I'm keeping the issue open for visibility to add this to docs in the future. If this is already tracked, I will close the issue, or the developers may feel free to do so 🫡
Comment by @NachoPicchu
RexSystem 1 vote originally by @NachoPicchu on GitHub
I work with split-horizon DNS. My IdP is reachable externally, but from Fluxers POV the address will resolve as a local one. So I'm hoping this is indeed considered a bug.