From 8beac702ea75c23ee880e674a8c10a613898d5da Mon Sep 17 00:00:00 2001 From: Gyula Kerezsi Date: Sat, 13 Jun 2026 17:13:30 +0300 Subject: [PATCH 1/5] Documentation: revise Arcane API key permissions requirements (#6770) Co-authored-by: shamoon <4887959+shamoon@users.noreply.github.com> --- docs/widgets/services/arcane.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/widgets/services/arcane.md b/docs/widgets/services/arcane.md index c8d88207f..6c59b9ee3 100644 --- a/docs/widgets/services/arcane.md +++ b/docs/widgets/services/arcane.md @@ -16,3 +16,5 @@ widget: key: your-api-key fields: ["running", "stopped", "total", "image_updates"] # optional ``` + +Using an api key for the widget requires permissions for: `containers:list` `images:list and `image-updates:read` From ce7594d0587b9a23c561cdc0197de8db0a562132 Mon Sep 17 00:00:00 2001 From: shamoon <4887959+shamoon@users.noreply.github.com> Date: Sat, 13 Jun 2026 08:12:32 -0700 Subject: [PATCH 2/5] Documentation: tweak auth docs --- README.md | 2 +- docs/installation/index.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 88d20b0ec..1648a0887 100644 --- a/README.md +++ b/README.md @@ -66,7 +66,7 @@ For configuration options, examples and more, [please check out the homepage doc Please note that when using features such as widgets, Homepage can access personal information (for example from your home automation system). To keep your information private, if Homepage is reachable from any untrusted network, it: 1. **must** sit behind a reverse proxy (and/or VPN) that enforces authentication, TLS, and strictly validates Host headers. -2. An optional built-in OIDC login flow is available (opt-in) offering a simple “authenticated or not” guard. +2. An optional built-in OIDC login flow or simple password login is available (opt-in) offering a simple “authenticated or not” guard. ## With Docker diff --git a/docs/installation/index.md b/docs/installation/index.md index d31f540c4..0f1f70e53 100644 --- a/docs/installation/index.md +++ b/docs/installation/index.md @@ -60,4 +60,4 @@ For OIDC login (overrides password login): - `HOMEPAGE_EXTERNAL_URL` (external URL to your Homepage instance; used for callbacks) - Optional: `HOMEPAGE_OIDC_NAME` (display name), `HOMEPAGE_OIDC_SCOPE` (defaults to `openid email profile`) -All app pages and `/api` routes will require a signed-in session. Static assets remain public. Homepage still does not implement per-user dashboards or roles; authentication is a simple gate only. +All app pages and `/api` routes will require a signed-in session. Static assets remain public. From 60338eab75fef62b80961adc4b95598be3b84325 Mon Sep 17 00:00:00 2001 From: shamoon <4887959+shamoon@users.noreply.github.com> Date: Sat, 13 Jun 2026 09:14:44 -0700 Subject: [PATCH 3/5] Remove this for safari --- src/pages/auth/signin.jsx | 2 -- 1 file changed, 2 deletions(-) diff --git a/src/pages/auth/signin.jsx b/src/pages/auth/signin.jsx index 2ff4b8220..bd352911d 100644 --- a/src/pages/auth/signin.jsx +++ b/src/pages/auth/signin.jsx @@ -128,8 +128,6 @@ export default function SignIn({ providers, settings }) { backgroundBrightness && `backdrop-brightness-${settings.background.brightness}`, )} > -
-
From 7cf9134c1fd6a523a7d82930aad77eb4571ff818 Mon Sep 17 00:00:00 2001 From: shamoon <4887959+shamoon@users.noreply.github.com> Date: Sat, 13 Jun 2026 09:14:36 -0700 Subject: [PATCH 4/5] Add oidc callback url --- docs/installation/index.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/installation/index.md b/docs/installation/index.md index 0f1f70e53..d310e2b00 100644 --- a/docs/installation/index.md +++ b/docs/installation/index.md @@ -61,3 +61,5 @@ For OIDC login (overrides password login): - Optional: `HOMEPAGE_OIDC_NAME` (display name), `HOMEPAGE_OIDC_SCOPE` (defaults to `openid email profile`) All app pages and `/api` routes will require a signed-in session. Static assets remain public. + +Configure your OIDC provider with the a callback URI like `https://homepage.example.com/api/auth/callback/homepage-oidc`. From 6f86b1800514c4c5788ebb2fbb951aaaef4866b7 Mon Sep 17 00:00:00 2001 From: shamoon <4887959+shamoon@users.noreply.github.com> Date: Mon, 15 Jun 2026 13:33:16 -0700 Subject: [PATCH 5/5] Fix (dev): exclude healthcheck from auth (#6776) --- docs/installation/index.md | 2 +- src/middleware.js | 2 +- src/middleware.test.js | 12 ++++++++++++ 3 files changed, 14 insertions(+), 2 deletions(-) diff --git a/docs/installation/index.md b/docs/installation/index.md index d310e2b00..9ed9b48ab 100644 --- a/docs/installation/index.md +++ b/docs/installation/index.md @@ -60,6 +60,6 @@ For OIDC login (overrides password login): - `HOMEPAGE_EXTERNAL_URL` (external URL to your Homepage instance; used for callbacks) - Optional: `HOMEPAGE_OIDC_NAME` (display name), `HOMEPAGE_OIDC_SCOPE` (defaults to `openid email profile`) -All app pages and `/api` routes will require a signed-in session. Static assets remain public. +All app pages and `/api` routes except `/api/healthcheck` will require a signed-in session. Static assets remain public. Configure your OIDC provider with the a callback URI like `https://homepage.example.com/api/auth/callback/homepage-oidc`. diff --git a/src/middleware.js b/src/middleware.js index 7d4052692..75242f9d6 100644 --- a/src/middleware.js +++ b/src/middleware.js @@ -20,7 +20,7 @@ export async function middleware(req) { return NextResponse.json({ error: "Host validation failed. See logs for more details." }, { status: 400 }); } - if (authEnabled) { + if (authEnabled && !new URL(req.url).pathname.startsWith("/api/healthcheck")) { const token = await getToken({ req, secret: authSecret }); if (!token) { const signInUrl = new URL("/auth/signin", req.url); diff --git a/src/middleware.test.js b/src/middleware.test.js index 5f24c0c23..72aea3872 100644 --- a/src/middleware.test.js +++ b/src/middleware.test.js @@ -85,6 +85,18 @@ describe("middleware", () => { expect(res).toEqual({ type: "next" }); }); + it("allows healthcheck requests without auth when host is allowed", async () => { + process.env.HOMEPAGE_AUTH_ENABLED = "true"; + process.env.HOMEPAGE_AUTH_SECRET = "secret"; + + const middleware = await loadMiddleware(); + const res = await middleware(createReq("localhost:3000", "http://localhost:3000/api/healthcheck")); + + expect(getToken).not.toHaveBeenCalled(); + expect(NextResponse.next).toHaveBeenCalled(); + expect(res).toEqual({ type: "next" }); + }); + it("redirects to signin when auth is enabled and no token is present", async () => { process.env.HOMEPAGE_AUTH_ENABLED = "true"; process.env.HOMEPAGE_AUTH_SECRET = "secret";