I
Immich•6mo ago
zer0

Paths used by public album sharing?

Hey y'all, I'm using client TLS auth. Which paths shall I exclude from auth for public albums to work correctly?
9 Replies
Immich
Immich•6mo ago
:wave: Hey @zer0, Thanks for reaching out to us. Please carefully read this message and follow the recommended actions. This will help us be more effective in our support effort and leave more time for building Immich :immich:. References - Container Logs: docker compose logs docs - Container Status: docker ps -a docs - Reverse Proxy: https://immich.app/docs/administration/reverse-proxy - Code Formatting https://support.discord.com/hc/en-us/articles/210298617-Markdown-Text-101-Chat-Formatting-Bold-Italic-Underline#h_01GY0DAKGXDEHE263BCAYEGFJA Checklist I have... 1. :blue_square: verified I'm on the latest release(note that mobile app releases may take some time). 2. :ballot_box_with_check: read applicable release notes. 3. :ballot_box_with_check: reviewed the FAQs for known issues. 4. :ballot_box_with_check: reviewed Github for known issues. 5. :ballot_box_with_check: tried accessing Immich via local ip (without a custom reverse proxy). 6. :ballot_box_with_check: uploaded the relevant information (see below). 7. :ballot_box_with_check: tried an incognito window, disabled extensions, cleared mobile app cache, logged out and back in, different browsers, etc. as applicable (an item can be marked as "complete" by reacting with the appropriate number) Information In order to be able to effectively help you, we need you to provide clear information to show what the problem is. The exact details needed vary per case, but here is a list of things to consider: - Your docker-compose.yml and .env files. - Logs from all the containers and their status (see above). - All the troubleshooting steps you've tried so far. - Any recent changes you've made to Immich or your system. - Details about your system (both software/OS and hardware). - Details about your storage (filesystems, type of disks, output of commands like fdisk -l and df -h). - The version of the Immich server, mobile app, and other relevant pieces. - Any other information that you think might be relevant. Please paste files and logs with proper code formatting, and especially avoid blurry screenshots. Without the right information we can't work out what the problem is. Help us help you ;) If this ticket can be closed you can use the /close command, and re-open it later if needed.
zer0
zer0OP•6mo ago
Caddy:
pics.{$NAME}.{$EXT_DOMAIN} {
tls /certs/pics.{$NAME}.{$EXT_DOMAIN}_ecc/fullchain.cer /certs/pics.{$NAME}.{$EXT_DOMAIN}_ecc/pics.{$NAME}.{$EXT_DOMAIN}.key {
client_auth {
mode require_and_verify
trust_pool file {
pem_file /etc/caddy/intermediate_ca.crt
pem_file /etc/caddy/root_ca.crt
}
}
}
reverse_proxy localhost:15864
}
pics.{$NAME}.{$EXT_DOMAIN} {
tls /certs/pics.{$NAME}.{$EXT_DOMAIN}_ecc/fullchain.cer /certs/pics.{$NAME}.{$EXT_DOMAIN}_ecc/pics.{$NAME}.{$EXT_DOMAIN}.key {
client_auth {
mode require_and_verify
trust_pool file {
pem_file /etc/caddy/intermediate_ca.crt
pem_file /etc/caddy/root_ca.crt
}
}
}
reverse_proxy localhost:15864
}
bo0tzz
bo0tzz•6mo ago
This way lies pain Try not using client auth, or use https://github.com/alangrainger/immich-public-proxy instead
zer0
zer0OP•6mo ago
i set up this instance for a total noob and for them it needs to work without any further set up installing the client cert was a hassle by itself 😦
bo0tzz
bo0tzz•6mo ago
This is simply not a good idea. Immich is not hands off, as the warning on the website says it's still under heavy development and often has breaking changes And even without that, Immich is a complex app that deals with very important data so it's not really for "a total noob" to manage 😅
zer0
zer0OP•6mo ago
No i am the one managing I just want all the user UI stuff to work like share links
bo0tzz
bo0tzz•6mo ago
IPP can be seamless if you set the external domain to point at it
zer0
zer0OP•6mo ago
but the regular non public links need to work too which is why there is client TLS oh wait this could work does this change the URL in any way?
Immich
Immich•6mo ago
This thread has been closed. To re-open, use the button below.

Did you find this page helpful?