docs: audiobookshelf is OIDC-only; no CrowdSec source needed #382
No reviewers
Labels
No labels
audit-work
bug
docs
general-admin
major-upgrade
needs-vps-sync
new-service
on-hold
outside-work
post-podman
renovate
upstream
vps
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
mysticalsoap/docker!382
Loading…
Reference in a new issue
No description provided.
Delete branch "docs/audiobookshelf-oidc-only"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
#378 asked for CrowdSec detection of Audiobookshelf's own password login on the Authelia-bypassed host. Checking it live answered both open questions in the issue and then made it moot: the user switched Audiobookshelf to OIDC-only.
Fix
Docs only.
setup/Media.md§8a: new step 3 — promote your account to Admin, untick Local, tick Auto Launch; the database edit that brings root back.Public-Exposure.md: the exposed-services row says password login is off.Auth-and-Security.md§ CrowdSec: why Audiobookshelf has no source, and thathttp-generic-401-bfalready covers itsPOST /loginif local login is ever re-enabled.Verification
Live, 2026-10-07, before the switch:
POST /loginreturned401through Traefik,OriginStatus401 in the access log.cscli explain --type traefikon that logged line, client address swapped for a public one (the LAN is whitelisted), ends withLePresidente/http-generic-401-bfas the firing scenario.X-Forwarded-For, so it already counts per client behind Traefik — no proxy-trust setting needed.After the switch:
GET /statusadvertisesauthMethods: ["openid"],authOpenIDAutoLaunch: true.POST /loginnow returns500(local strategy unregistered), nothing to brute-force.UserControllerandApiKeyControllercheckisRoot; authentication settings are admin-level.🤖 Generated with Claude Code