Skip to main content

Bypass Authorization for Specific URIs

A bypass lets a matching request proceed without a credential or authenticated identity. Use it for deliberately public resources, such as a health endpoint, not as a remedy for a login loop.

# Inside the policy:
bypass uri exact /health
bypass uri prefix /public/
allow roles app/member
StrategyMatch
exactThe whole path
partialA substring anywhere in the path
prefixBeginning of the path
suffixEnd of the path
regexA Go regular expression; anchor it when the whole path matters

prefix /public also matches /publicity. Use an exact path plus a slash-ended prefix when granting a directory tree. Query parameters do not turn a protected path into a public one.

The released implementation checks decoded and cleaned path interpretations; ambiguous encodings must not create a bypass. Test /health, /health-extra, /public/file, and a protected sibling separately. The direct OAuth policy's reserved callback/logout paths are handled by its own flow.

Configured identity headers are cleared even on bypass. The backend must treat a public request as unauthenticated. For complex public/private routing, separate Caddy handlers can make the boundary easier to review than a broad bypass rule.