From d5aa4e9354cf5b2d0f0cfb8dcbf8b5500502138e Mon Sep 17 00:00:00 2001 From: Zef Hemel Date: Wed, 10 Dec 2025 17:08:30 +0100 Subject: [PATCH] Clarify authentication proxies --- website/Authentication Proxy.md | 8 ++++++++ website/Authentication.md | 2 ++ 2 files changed, 10 insertions(+) create mode 100644 website/Authentication Proxy.md diff --git a/website/Authentication Proxy.md b/website/Authentication Proxy.md new file mode 100644 index 00000000..5110fe18 --- /dev/null +++ b/website/Authentication Proxy.md @@ -0,0 +1,8 @@ +In case you would like to run SilverBullet behind an authentication proxy (such as Authelia, Authentik or the ones integrated with Cloudflare Zero Trust or Pangolin) there is one key configuration tweak you need to make: + +**You must exclude a few paths from authentication**. If you don’t do this a lot of PWA functionality may not work and SilverBullet may break in unexpected ways. Doing this is perfectly safe, it just gives browsers unauthorized access to some client code, not any of your content. + +In your configuration add **rules to allow unauthenticated access** for the following paths: + +* `/service_worker.js` +* `/.client/*` diff --git a/website/Authentication.md b/website/Authentication.md index 61180954..77954abb 100644 --- a/website/Authentication.md +++ b/website/Authentication.md @@ -9,3 +9,5 @@ docker run -e SB_USER=pete:1234 ... Will let `pete` authenticate with password `1234`. For more options see [[Install/Configuration]]. + +Alternatively, or in addition, you can also use an [[Authentication Proxy]]. \ No newline at end of file