<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OIDC auth for public facing access?]]></title><description><![CDATA[<p dir="auto">I'm trying to figure out how to better protect my public facing services. IMHO, If it's not obvious, the LLM assisted exploits are only going to improve.  Finding 0-days seems to be a weekly thing now and it's just the beginning.</p>
<p dir="auto">I think it'd be cool to have pfsense redirect a (incoming) user to /auth endpoint somewhere before accessing any of my services. The user has to login to whatever IDP and then get redirected back to /auth with a jwt or something that the backend app could use to determine if the login succeeded. If so, then some authz check with user@gmail.com that you want to allow.  If all good, drop the user IP into a pfsense allow list for 12 hours or something.</p>
<p dir="auto">Ya I could just wireguard/tailscale everyone, but I run Nextcloud and share files with people sometimes.  WG will never fly for one-off file shares. A redirect could be automated where the user installs nothing.</p>
<p dir="auto">Other options is just move all my public stuff to cloud providers but that just adds up to cash I don't have laying around to burn.</p>
<p dir="auto">I'm probably trying to reinvent the wheel. Anyone know if something like this already exists?</p>
]]></description><link>https://forum.netgate.com/topic/200693/oidc-auth-for-public-facing-access</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Jul 2026 17:54:59 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/200693.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 16 May 2026 12:02:30 GMT</pubDate><ttl>60</ttl></channel></rss>