Skip to content

[BUG] conflicting auth module headers #1125

Description

@nebula-it

Describe the Bug

Since v5.2 access to pages protected by TinyAuth are failing with error:

WRN Request carries headers for multiple auth modules, possible spoofing attempt, denying stream=app
ERR Failed to get proxy context from request error="conflicting auth module headers" stream=app

How to Reproduce

  1. Setup tinyauth with ingress-nginx as per this doc
  2. Try to access the host protected by tinyauth

Expected Behavior

After auth user gets redirected to actual host/page

Additional Context

Logs

WRN Request carries headers for multiple auth modules, possible spoofing attempt, denying stream=app
ERR Failed to get proxy context from request error="conflicting auth module headers" stream=app

Operating System

No response

Browser

No response

Tinyauth Version

v5.2.0

Docker Version (if applicable)

No response

Human Written Confirmation

  • I confirm this issue was written by me and not generated by an LLM or AI assistant.

Activity

  1. coral-hungus commented on Sep 10, 2026

    @coral-hungus

    I am seeing the same behavior using TinyAuth with SWAG. Versions prior to 5.2 work fine.

  2. steveiliop56 commented on Sep 10, 2026

    @steveiliop56
    Member

    Hello,

    Yes this is a security improvements that helps mitigate header injection. The reason this error appears is because Tinyauth sees headers for both X-Forwarded-Host/X-Forwarded-URI and X-Original-URL.

    For SWAG, @coral-hungus please see the SWAG guide in the documentation with the updated config. We are also working with the LinuxServer team for updated sample files.

    @nebula-it are you using an internal connection with http://tinyauth.tinyauth.svc.cluster.local:3000/api/auth/nginx as the URL for the nginx.ingress.kubernetes.io/auth-url? Are you sure that no custom headers are being send to Tinyauth? Technically you shouldn't face this issue as ingress Nginx is supposed to only send X-Original-URL.

  3. coral-hungus commented on Sep 10, 2026

    @coral-hungus

    @steveiliop56 thanks for pointing out the documentation. That did the trick.

  4. nebula-it commented on Sep 10, 2026

    @nebula-it
    Author

    Nope, I'm using the ingress for tinyauth i.e nginx.ingress.kubernetes.io/auth-url: https://tinyauth.example.com/api/auth/nginx
    I have combed through the nginx config and dont see anything that would add additional headers. Is there any way to log those? I tried TINYAUTH_LOG_LEVEL: trace but still dont get much more info about the headers causing issue.

  5. steveiliop56 commented on Sep 10, 2026

    @steveiliop56
    Member

    @nebula-it please use the internal connection instead. The external one is prone to messing with the headers (with/without the latest update) and causing a lot of issues. That's probably what's happening right now.

  6. nebula-it commented on Sep 10, 2026

    @nebula-it
    Author

    That fixed it. Thank you

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions