Proxy *** challenge through login server for multi-domain support

Fixkamo-login
Shipped
April 17, 2026 at 1:36 AM UTC
Author
Kamo
Commit
17d8566

Replaces direct cross-origin fetch to capcha.{domain}/api/challenge with a same-origin proxy at /api/capcha/challenge. The previous approach required a valid TLS cert on the capcha.* subdomain before the widget could load, causing 'Verification failed' for any org domain on first use. The proxy routes through the internal k8s service, making *** work on any domain that has login.* configured without additional DNS or cert setup.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing