Monitoring Redirects Can Create False Green Probes
A health probe that automatically follows redirects may end on an authentication page and report successful HTTP even though the original service route is wrong.
A health probe that automatically follows redirects may end on an authentication page and report successful HTTP even though the original service route is wrong.
Firmware cannot complete an interactive Authelia login, but bypassing authentication entirely would expose the OTA control plane.
One identity portal can protect many subdomains only if browser cookie scope and request behavior match the intended trust boundary.
A firmware client cannot solve an interactive login flow, and treating the redirect as success hides the real authentication failure.
Synthetic health checks normally have no browser cookie, so anonymous AuthRequest logs can be completely healthy behavior.
A longer browser cookie does not help if the server forgets the session behind it.
A session can have an idle timeout, a hard lifetime and a trusted-browser persistence policy at the same time.
Human federation should be added after the secret authority is stable, not mixed into the initial bootstrap trust ceremony.
A two-factor login system naturally records failed credentials, expired sessions and rejected access, so any single failure is not automatically an attack.
The six-digit code comes from a shared TOTP secret and time step; Google Authenticator is only one compatible client.
Cross-subdomain authentication only works predictably when cookie scope and redirect boundaries match the domain design.
A public request can fail before reaching Authelia, inside the authentication flow, or after authentication while the upstream application is unavailable.
Persistent SSO works better when ephemeral session state and durable identity-provider state are not confused.
Long-lived trusted-browser sessions change the authentication risk model and should be chosen deliberately.
Putting MFA in front of each application separately creates duplicated policy; Authelia gives the protected subdomains one identity boundary.