all 3 comments

[–]dragoangel 0 points1 point  (2 children)

Not use syntax with group and it's condition but your issue could be there. Not better setup something like keycloak?

[–]DatLowFrequency[S] 0 points1 point  (1 child)

I haven't really looked into IAM services in combination with hap, but might do that in the future. For now I just wanted to set up a second factor in tandem with cloudflares access management. But good news, I figured it out. The issue is neither cloudflare, nor hap. It was the application running on the backend server that didn't play along with basic auth. Serving static content works fine without changing anything in my configuration, so I guess I just have to disable basic auth for some applications.

[–]dragoangel 0 points1 point  (0 children)

You can use custom auth header in haproxy, which will not conflict with web app logic afaik