How to use FIDO2 with Discourse behind a reverse proxy?

AI-generated summary

The discussion revolves around using FIDO2 with Discourse behind a reverse proxy. JonahAragon1 is experiencing issues with Yubikey 2FA and Passkey logins not working behind a Cloudflare Tunnel. pmusaraj suggests overriding a temporary setting and using the --forward-host flag, but this doesn’t resolve the issue.

After troubleshooting, pmusaraj reveals that the problem lies in the server thinking it’s not running on the same hostname as the browser is requesting. JonahAragon1 checks the Discourse.current_hostname and finds it matches the URL used to access the site. However, pmusaraj suspects a potential http vs https issue.

Further investigation shows that Discourse.base_url is set to an http:// URL. JonahAragon1 realizes that enabling the force https setting in Discourse resolves the issue. The setting was previously unnecessary but became required after adding another reverse proxy. With the solution found, JonahAragon1 thanks pmusaraj for their help.

Has anyone ever figured out how to use FIDO2 with Discourse behind a reverse proxy? I’m having this issue using the web.socketed.template.yml template with a forum behind a Cloudflare Tunnel.

Neither Yubikey 2FA nor the new Passkey logins are working for me.

Is this on a dev environment? You might need to override this bit temporarily:

And it is also likely helpful to use the --forward-host flag when running the server, i.e. bin/ember-cli -u --forward-host.

No, this is a production install.

What error messages are you getting?

What is the full URL of the failed request, /auth.json?

Ah, no: /session/passkey/auth.json

Ok, so your server thinks that it is not running on the hostname that the browser is requesting. The security key / passkey generation procedure has to ensure that the the hostname of the browser matches that of the server (keys are generated per hostname).

Can you log into your Rails console and check what the output of Discourse.current_hostname is? If it doesn’t match the URL you use to access the site, that’s the problem.

Note, this could be a http vs https issue as well. I see the logo is looking for a URL under http:// on your site.

Discourse.current_hostname does match the URL I use to access the site. Is there a way to see what Discourse thinks the hostname my browser is requesting is?

What do you get for Discourse.base_url in the console?

Ah, that is set to an http:// URL (with the correct hostname). I’m using the setup described here to make Discourse accessible to Cloudflare Tunnel:

Oh, I think I got it. Enabling the force https setting in Discourse seems to have fixed it, I’m not sure why it was off. I don’t think it was necessary in the default config before adding another reverse proxy in front of it. Thanks for your help!