docs: audiobookshelf is OIDC-only; no CrowdSec source needed #382

Merged
mysticalsoap merged 1 commit from docs/audiobookshelf-oidc-only into trunk 2026-10-07 17:51:33 -04:00
Owner

Problem

#378 asked for CrowdSec detection of Audiobookshelf's own password login on the Authelia-bypassed host. Checking it live answered both open questions in the issue and then made it moot: the user switched Audiobookshelf to OIDC-only.

Fix

Docs only.

  • setup/Media.md §8a: new step 3 — promote your account to Admin, untick Local, tick Auto Launch; the database edit that brings root back.
  • Public-Exposure.md: the exposed-services row says password login is off.
  • Auth-and-Security.md § CrowdSec: why Audiobookshelf has no source, and that http-generic-401-bf already covers its POST /login if local login is ever re-enabled.

Verification

Live, 2026-10-07, before the switch:

  • A bad POST /login returned 401 through Traefik, OriginStatus 401 in the access log.
  • cscli explain --type traefik on that logged line, client address swapped for a public one (the LAN is whitelisted), ends with LePresidente/http-generic-401-bf as the firing scenario.
  • Audiobookshelf's own limiter (40 per 10 min) keys clients via the request-ip library, which reads X-Forwarded-For, so it already counts per client behind Traefik — no proxy-trust setting needed.

After the switch:

  • GET /status advertises authMethods: ["openid"], authOpenIDAutoLaunch: true.
  • A bad POST /login now returns 500 (local strategy unregistered), nothing to brute-force.
  • Root-gated code paths in the running image (2.37.1): only UserController and ApiKeyController check isRoot; authentication settings are admin-level.

🤖 Generated with Claude Code

## Problem #378 asked for CrowdSec detection of Audiobookshelf's own password login on the Authelia-bypassed host. Checking it live answered both open questions in the issue and then made it moot: the user switched Audiobookshelf to OIDC-only. ## Fix Docs only. - `setup/Media.md` §8a: new step 3 — promote your account to Admin, untick Local, tick Auto Launch; the database edit that brings root back. - `Public-Exposure.md`: the exposed-services row says password login is off. - `Auth-and-Security.md` § CrowdSec: why Audiobookshelf has no source, and that `http-generic-401-bf` already covers its `POST /login` if local login is ever re-enabled. ## Verification Live, 2026-10-07, before the switch: - A bad `POST /login` returned `401` through Traefik, `OriginStatus` 401 in the access log. - `cscli explain --type traefik` on that logged line, client address swapped for a public one (the LAN is whitelisted), ends with `LePresidente/http-generic-401-bf` as the firing scenario. - Audiobookshelf's own limiter (40 per 10 min) keys clients via the request-ip library, which reads `X-Forwarded-For`, so it already counts per client behind Traefik — no proxy-trust setting needed. After the switch: - `GET /status` advertises `authMethods: ["openid"]`, `authOpenIDAutoLaunch: true`. - A bad `POST /login` now returns `500` (local strategy unregistered), nothing to brute-force. - Root-gated code paths in the running image (2.37.1): only `UserController` and `ApiKeyController` check `isRoot`; authentication settings are admin-level. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
docs: audiobookshelf is OIDC-only; no CrowdSec source needed
All checks were successful
validate / validate (pull_request) Successful in 25s
e1f09fcf52
Password login is switched off in Audiobookshelf, so the host has no
credential form left to guess at and #378 needs no parser. The setup
page gets the step that makes the switch (admin type first, then untick
Local), with the database edit that brings root back. The CrowdSec
section records why the app has no source and what covers it if local
login ever returns.

Closes #378

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
mysticalsoap deleted branch docs/audiobookshelf-oidc-only 2026-10-07 17:51:34 -04:00
Sign in to join this conversation.
No description provided.