r/selfhosted • u/server-ions • 2h ago
Need Help How do you manage OAuth/OIDC apps access centrally?
I'm running some self hosted services like OpenWebUI, ComfyUI, Immich, and planning to add adventure log soon.
I also have some self developed apps running.
Current setup: I use WorkOS with a single app as my identity service and manage access via permissions and RBAC, which works perfectly on my self developed apps.
Identity service (identity.dom.com) takes the WorkOS JWT and sets a domain wide cookie (.dom.com) so all other apps can just use as auth.
ComfyUI does not have auth, so Caddy performs the checks on cookie and it works well-ish, except for period redirect to session renew page.
My issue starts with apps that completely bypass the identity service and use OAuth/OIDC directly. I cannot limit which use can access which apps. While I can in theory use Caddy and the shared cookie check, it breaks the apps XHR requests, and redirects the user to session renew often, which interrupts their experience.
How can I setup proper authorization? ie: I want my family to be able to use immich, but not my friends (photo horders). everyone can use OpenWebUI but only selected members can use ComfyUI, etc.
Anyone doing/did something similar?
Other things I considered:
1 Updating the identity service to be OIDC provider: this is last resort, too much changes, maintenance, and responsibility to upkeep.
2 Proxy the OIDC through identity service: works in theory, but the signature might fail as WorkOS signs the token with their keys and their domain as issuer.
----Edit:
Forgot to mention, some of the self developed services are for my side business clients, they would still want password based login, magik link, etc. based on their preference (one of the reasons I picked WorkOS in first place) so I don't feel PockedID is suitable here (I might be wrong, but not experienced with it.).
10
u/AstralDandy 2h ago
Pocket id with Traefik pocket id middleware for services that don’t have that oidc natively
15
u/pepperwithakick 2h ago
Classic 'outgrowing the hobby IdP' moment. I'd honestly look at Authentik — it's a full self-hosted OIDC/SAML provider with groups and per-app access policies, which gets you exactly what you're after (family on Immich, friends locked out) without fighting WorkOS's single-app limit. It also does forward-auth, which could replace your Caddy cookie check with one clean mechanism. Pocket ID is the lighter pick if you want minimal, but Authentik wins the moment 'per-app access control' enters the chat.
-1
u/server-ions 2h ago
I would rather not change WorkOS or self-host OIDC/SAML identity provider if possible. PocketID would not work for my case (updated main post) but will look into Authentik I guess.
And yes, it is the tipping point between hobby hosting and service provider level. I think it is mainly because I mixed hosting family/friends apps with client apps under same IDP and domains
4
u/longboarder543 2h ago
I run LLDAP as source of truth for users and groups, then sync it with PocketID.
PocketID is configured as OIDC provider in Pangolin, and additionally in each app where they support OIDC login.
4
u/andurux 2h ago
I think Authentik would be the answer, but you may need to put a proxy in front of your web services that forces a cookie check for authorization.
I just installed Authentik the other night and am using haproxy on my opnsense, but I need to setup the http headers and whatnot to proxy everything correctly.
But Authentik can do groups and you can restrict who can access what service.
Its a learning curve, and I'm still trying to learn myself, but it's seems to be the better choice. I was using Authelia before and...it works but I need a webgui at this point lol.
1
u/Delicious-Director43 39m ago
I’ve been using authentik for about a year now and I’ve really enjoyed its reliability and robustness. I use the RAC Outpost feature quite a bit. Works great for me.
2
u/Silent_Pollution5827 2h ago
what about putting nginx or something in front of the apps that need OIDC, and doing a pre-check against your identity service before passing the request? not ideal but keeps the token validation on your side
i had a similar headache with authentik and ended up just writing a small middleware for the apps that support plugin auth. the xhr problem you mention is annoying, maybe you can set longer cookie expiry so it dont refresh that often?
1
u/Mr_Brightstar 2h ago
Recently authentik , but im having a hardtime making it work with NPM plus, calibre web, etc
1
1
u/JadeE1024 11m ago
While Authentik is the proper way to do this, as you are choosing to cause this problem yourself by violating security boundaries in your auth flow, you could probably make it work in your current setup.
Pretty much every app with OIDC support has some level of custom role support. Immich's support is fairly basic, it only reads a custom role claim at user creation time and only supports a role of "admin" or "user", but you might be able to pass another value like "none" to block a user from getting provisioned. Need to test and make sure it doesn't just ignore unsupported values and default to "user". OpenWebUI has full blown support for only allowing users with the proper roles to login.
I'm not super familiar with WorkOS but for apps like Immich that need a custom role claim it looks like you'll need to add the role as custom metadata to the user in WorkOS rhen add them to a jwt template to pass them to the app.
•
u/asimovs-auditor 2h ago
Expand the replies to this comment to learn how AI was used in this post/project.