authentik · Issues· 1106 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #24182
LDAP outpost bind unusable on 2026.2.6: post-bind "failed to get user info" 403 without a flow session, but a User-Login stage triggers "exceeded stage recursion depth" (regression, cf #18421)
status/staleUpdated Sep 18, 2026 - #26138
CSRF Failed: "X-Authentik-Csrf HTTP header has incorrect length" recurring across versions and flows (password change, token creation, WebAuthn setup)
bugUpdated Sep 17, 2026 - #26036
providers/ldap: support fetching users/groups on-demand instead of caching the entire directory in "cached" search/bind mode
enhancementenhancement/confirmedUpdated Sep 17, 2026 - #26057
Kerberos and LDAP sources do not create source connections for existing users
bugstatus/reviewingUpdated Sep 17, 2026 - #26060
Kerberos sync job stops working after a while
bugbug/confirmedUpdated Sep 17, 2026 - #26073
Recovery flow Email stage renders and creates verification token, but send_mail task is never enqueued
bugstatus/awaiting-contributorUpdated Sep 17, 2026 - #26083
Property Mapping - Define a 'source of truth' source that wins when multiple sources are used.
enhancementstatus/reviewingUpdated Sep 17, 2026 - #26125
2026.8.2 Embedded proxy outpost authenticates as akadmin instead of its own service account, causing 403 on /api/v3/outposts/proxy/ (Not Found on all proxied apps)
bugstatus/reviewingUpdated Sep 17, 2026 - #26214
Installation on Podman
Updated Sep 17, 2026 - #26217
Resend email confirmation notification is not working
bugUpdated Sep 17, 2026 - #26232
Worker never establishes LISTEN subscription for task queue — all tasks stuck in "queued" indefinitely (reproduces on 2026.8.0 and 2026.8.2)
bugtriageUpdated Sep 17, 2026 - #25996
Upgrade 2026.5.7 → 2026.8.2 fails: InconsistentMigrationHistory — authentik_core.0064_..._idx applied before its 2026.8 dependency authentik_core.0063_actor / authentik_rbac.0011
bug/confirmedtriageUpdated Sep 17, 2026 - #26230
Allow email MFA authenticators to share email addresses across users
enhancement/confirmedUpdated Sep 17, 2026 - #26228
Standalone proxy outpost: cookie_domain is silently clobbered when multiple Providers share the filesystem session store (forward_domain + forward_single mix)
Updated Sep 17, 2026 - #25799
Add an API endpoint to retrieve all effective entitlements for a specific user
enhancementenhancement/confirmedUpdated Sep 16, 2026