A self-hosted single sign-on setup that puts password + TOTP in front of apps that have no auth of their own — without touching the apps.
The trick is one nginx directive: auth_request. Before nginx proxies a
request upstream, it fires an internal subrequest to another endpoint. 2xx means
the request proceeds. 401/403 means it's rejected. That's the entire mechanism.
Authelia is just a daemon that answers that
subrequest, based on a session cookie and a policy file.