Authelia+Jellyfin+Swag(Nginx)认证通过后出现Nginx 500错误求助
1. 缺失Authelia服务器级配置引入
你的jellyfin.subdomain.conf中注释明确提到,启用Authelia需要在server块中包含authelia-server.conf,但当前配置仅在location /中引入了authelia-location.conf。authelia-server.conf定义了@authelia_proxy_signin这个关键的重定向location,缺少它会导致认证完成后Nginx无法正确处理跳转逻辑,直接触发500错误。
修复步骤:
在server块内(比如include /config/nginx/ssl.conf;之后)添加以下配置:
include /config/nginx/authelia-server.conf;
2. Set-Cookie头的空值问题
你的authelia.conf中直接使用add_header Set-Cookie $set_cookie;,当$set_cookie为空时,会生成无效的空Set-Cookie头,这可能导致Nginx返回500错误。
修复步骤:
修改该行,添加条件判断,仅当变量有值时才添加响应头:
if ($set_cookie) { add_header Set-Cookie $set_cookie; }
3. Socket路径未启用Authelia认证
当前location ~ (/jellyfin)?/socket没有包含Authelia的认证配置,会导致WebSocket连接绕过双因素认证,存在安全风险。虽然这不是当前500错误的直接原因,但建议补上:
修复步骤:
在socket的location块中添加Authelia配置引入:
location ~ (/jellyfin)?/socket { include /config/nginx/authelia-location.conf; # 添加此行 include /config/nginx/proxy.conf; include /config/nginx/resolver.conf; set $upstream_app jellyfin; set $upstream_port 8096; set $upstream_proto http; proxy_pass $upstream_proto://$upstream_app:$upstream_port; }
4. 验证Authelia配置中的路径设置
确认Authelia的configuration.yml中已正确设置path: "authelia",这是authelia.conf注释要求的,确保Nginx能正确转发认证请求到Authelia的API端点。
完成上述修改后,重启Swag容器使配置生效,再测试认证流程。
内容的提问来源于stack exchange,提问作者Kodsama

