Checklist
- Have you pulled and found the error with
jc21/nginx-proxy-manager:latest docker image?
- Are you sure you're not using someone else's docker image?
- Have you searched for similar issues (both open and closed)?
Describe the bug
After updating the Nginx Proxy Manager Docker image, authentication through Tinyauth started timing out for multiple protected applications.
Both Open WebUI and Paperless-ngx are behind Nginx Proxy Manager and use the same Tinyauth authentication configuration. After the NPM update:
• Open WebUI login failed.
• Paperless-ngx login returned HTTP 500.
• NPM logs showed that the Tinyauth auth_request subrequest timed out.
• The issue affected multiple applications, so it appears to be related to NPM/Tinyauth proxy handling rather than either application.
Rolling back the Nginx Proxy Manager Docker image resolved the issue.
Environment
• Nginx Proxy Manager: [v2.15.1]/latest] before update
• Nginx Proxy Manager version after update: [v2.16.0/latest]
• Installation: Docker Compose
• Tinyauth: [ghcr.io/steveiliop56/tinyauth:v5]
• Docker version: [29.8.0, build 88096ef]
• Host OS: [Debian 12]
• Architecture: [amd64]
Network/authentication setup
The applications are exposed through Nginx Proxy Manager and protected with Tinyauth using an NPM auth_request subrequest.
The relevant authentication endpoint is:
http://172.19.0.3:3000/api/auth/nginx
The NPM configuration uses a subrequest similar to:
/tinyauth
The exact Tinyauth configuration and secrets can be provided if required, with sensitive values removed.
Nginx Proxy Manager Version
To Reproduce
Steps to reproduce the behavior:
• Run Nginx Proxy Manager in Docker.
• Configure a Proxy Host protected by Tinyauth using the /api/auth/nginx auth endpoint.
• Place multiple web applications behind the proxy.
• Update the Nginx Proxy Manager Docker image.
• Try to authenticate to the protected applications.
Expected behavior
Nginx Proxy Manager should send the authentication subrequest to Tinyauth and receive a response within a reasonable time. Protected applications should be able to complete login normally.
Operating System
Debian 12
Additional context
NPM also logged the following warning for Open WebUI requests:
using uninitialized "trust_forwarded_proto" variable
Checklist
jc21/nginx-proxy-manager:latestdocker image?Describe the bug
After updating the Nginx Proxy Manager Docker image, authentication through Tinyauth started timing out for multiple protected applications.
Both Open WebUI and Paperless-ngx are behind Nginx Proxy Manager and use the same Tinyauth authentication configuration. After the NPM update:
Rolling back the Nginx Proxy Manager Docker image resolved the issue.
Environment
Network/authentication setup
The applications are exposed through Nginx Proxy Manager and protected with Tinyauth using an NPM auth_request subrequest.
The relevant authentication endpoint is:
http://172.19.0.3:3000/api/auth/nginx
The NPM configuration uses a subrequest similar to:
/tinyauth
The exact Tinyauth configuration and secrets can be provided if required, with sensitive values removed.
Nginx Proxy Manager Version
To Reproduce
Steps to reproduce the behavior:
• Run Nginx Proxy Manager in Docker.
• Configure a Proxy Host protected by Tinyauth using the /api/auth/nginx auth endpoint.
• Place multiple web applications behind the proxy.
• Update the Nginx Proxy Manager Docker image.
• Try to authenticate to the protected applications.
Expected behavior
Nginx Proxy Manager should send the authentication subrequest to Tinyauth and receive a response within a reasonable time. Protected applications should be able to complete login normally.
Operating System
Debian 12
Additional context
NPM also logged the following warning for Open WebUI requests:
using uninitialized "trust_forwarded_proto" variable