What authelia/authelia shipped
Written by FoxPlug from public releases; not affiliated with Authelia. An automatic summary of the public release, pull request and commit data of github.com/authelia/authelia. Authelia did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Authz endpoints now derive response headers from user attributes, allowing any standard, extended, or custom attribute to be sent to the proxy instead of just the defaults. Pull request #9346
- Configuration files now support TOML and JSON formats in addition to YAML, with format determined by file extension. Pull request #9223
- Added config.filters.values option to load YAML, JSON, or TOML values files that are deep-merged and exposed to the template filter as .Values. Pull request #9230
- Template filter delimiters are now customizable via --config.filters.template.delimiter.left and --config.filters.template.delimiter.right options. Pull request #11907
- OTP input styling now uses theme tokens correctly when using the OLED theme. Pull request #13252
- Web dependencies refactored to replace clsx and tailwind-merge with cn package. Pull request #13279
- OIDC integration documentation updated with Vault configuration examples. Pull request #13188
- OIDC integration documentation updated for OwnCloud with version bump and desktop client notes. Pull request #13277
- Container image tagging now normalizes branch names to comply with registry tag requirements. Pull request #13249
- CI pipeline reorganized into logical Buildkite group steps for better readability. Pull request #13258
Why it matters
This week brings significant configuration flexibility improvements with TOML and JSON support, customizable template delimiters, and the ability to map any user attribute to response headers. These features enable more sophisticated deployment scenarios and better integration with various infrastructure setups.
Changelog entry
- feat(handlers): authz endpoints now derive response headers from user attributes Pull request #9346
- feat(configuration): add support for TOML and JSON config file formats Pull request #9223
- feat(configuration): add template filter values files with deep merge support Pull request #9230
- feat(configuration): customizable template filter delimiters Pull request #11907
- fix(web): OTP input styling now respects theme tokens in OLED mode Pull request #13252
- refactor(web): replace clsx and tailwind-merge with cn package Pull request #13279
- docs(oidc): updated Vault integration guide Pull request #13188
- docs(oidc): updated OwnCloud integration documentation Pull request #13277
- docs(oidc): updated Mastodon integration guide Pull request #13241
- docs(oidc): updated Gitea integration guide Pull request #13145
Authelia now supports TOML and JSON config formats, customizable template delimiters, and derives authz headers from any user attribute. Better flexibility for your deployment.
This week's Authelia updates focus on configuration flexibility and integration depth. Support for TOML and JSON formats, customizable template delimiters, and the ability to map any user attribute to authz response headers give operators more control over their deployments. We've also enhanced OIDC integration docs and improved web styling for OLED themes.
Week of September 14, 2026
What shipped
- Version 4.39.28 released with fixes for consent redirects, Envoy authz headers, and OIDC consent duplication. Release
- Added
/api/health/extendedendpoint that checks database and authentication backend connectivity, improving load balancer routing decisions. Pull request #13127 - Second factor registration is now offered in user settings even when no access control rules explicitly require two-factor authentication. Pull request #13156
- Operators can now configure a custom registration URL to point users toward external account provisioning systems. Pull request #13093
- TOTP authenticator application suggestions are now configurable instead of hardcoded to Google Authenticator. Pull request #13095
- Filesystem notifier now supports FIFO destinations without panicking during startup checks or synchronization. Pull request #11903
- OIDC conformance suite image pinned by digest to satisfy supply chain security checks. Pull request #13172
- Scorecard file-based checks integrated into the lint script to catch issues at commit time instead of waiting for weekly runs. Pull request #13178
Why it matters
This week's updates improve deployment flexibility and observability. Operators gain control over authenticator recommendations and registration flows, while infrastructure improvements ensure load balancers can route traffic only to healthy nodes with functional backends.
Changelog entry
- Release v4.39.28 Release
- Server: add verbose health check endpoint at /api/health/extended Pull request #13127
- Handlers: offer second factor registration for elevation Pull request #13156
- Authentication: add registration custom URL configuration Pull request #13093
- TOTP: make suggested authenticator app configurable Pull request #13095
- Notification: support FIFO destinations for filesystem notifier Pull request #11903
- Build: pin OIDC conformance suite image by digest Pull request #13172
- CI: add scorecard linter to file-based checks Pull request #13178
Authelia 4.39.28 ships with health checks that verify backend connectivity, configurable TOTP apps, custom registration URLs, and FIFO notifier support.
Authelia 4.39.28 is available. This release improves observability with extended health checks that verify database and authentication backend connectivity, giving load balancers better routing decisions. Operators can now customize TOTP authenticator recommendations and point users to external registration systems. The filesystem notifier gains FIFO support, and supply chain security is enhanced with pinned container images.