since upgrading Pangolin from 1.17.0 to 1.17.1, I am no longer able to log in. The same setup worked without any issues on version 1.17.0.
What happens:
I open the login page
I enter my username and password (Or Login with Passkey)
I am prompted for my TOTP/Passkey
After successful verification, instead of being logged in, I am redirected back to the login page
This loop repeats indefinitely
Environment:
Edition: Enterprise
Previous version: 1.17.0 (working)
Current version: 1.17.1 (issue started)
Deployment method: Docker
Authentication method: Passkey and username/password with TOTP
Logs:
pangolin | Making security key start request to:http://localhost:3000/api/v1/auth/security-key/authenticate/startpangolin | Making security key verify request to:http://localhost:3000/api/v1/auth/security-key/authenticate/verifypangolin | Making login request to:http://localhost:3000/api/v1/auth/loginpangolin | Making login request to:http://localhost:3000/api/v1/auth/loginpangolin | Making security key start request to:http://localhost:3000/api/v1/auth/security-key/authenticate/startpangolin | Making security key verify request to:http://localhost:3000/api/v1/auth/security-key/authenticate/verify
Observed behavior:
Authentication appears to succeed
The system repeatedly initiates authentication again
No session is established
User is redirected back to the login page
Expected behavior:
After successful authentication, the user should be logged in and redirected to the dashboard.
Environment
OS Type & Version: Docker
Pangolin Version: Latest
Gerbil Version: Latest
Traefik Version: Latest
Newt Version: Latest
Olm Version: (if applicable)
Originally created by @Blacks-Army on GitHub (Apr 14, 2026).
Original GitHub issue: https://github.com/fosrl/pangolin/issues/2859
### Describe the Bug
Hi,
since upgrading Pangolin from 1.17.0 to 1.17.1, I am no longer able to log in. The same setup worked without any issues on version 1.17.0.
**What happens:**
1. I open the login page
2. I enter my username and password (Or Login with Passkey)
3. I am prompted for my TOTP/Passkey
4. After successful verification, instead of being logged in, I am redirected back to the login page
5. This loop repeats indefinitely
Environment:
- Edition: Enterprise
- Previous version: 1.17.0 (working)
- Current version: 1.17.1 (issue started)
- Deployment method: Docker
- Authentication method: Passkey and username/password with TOTP
**Logs:**
```yaml
pangolin | Making security key start request to: http://localhost:3000/api/v1/auth/security-key/authenticate/start
pangolin | Making security key verify request to: http://localhost:3000/api/v1/auth/security-key/authenticate/verify
pangolin | Making login request to: http://localhost:3000/api/v1/auth/login
pangolin | Making login request to: http://localhost:3000/api/v1/auth/login
pangolin | Making security key start request to: http://localhost:3000/api/v1/auth/security-key/authenticate/start
pangolin | Making security key verify request to: http://localhost:3000/api/v1/auth/security-key/authenticate/verify
```
**Observed behavior:**
- Authentication appears to succeed
- The system repeatedly initiates authentication again
- No session is established
- User is redirected back to the login page
**Expected behavior:**
After successful authentication, the user should be logged in and redirected to the dashboard.
### Environment
- OS Type & Version: Docker
- Pangolin Version: Latest
- Gerbil Version: Latest
- Traefik Version: Latest
- Newt Version: Latest
- Olm Version: (if applicable)
<!-- gh-comment-id:4247308254 -->
@oschwartz10612 commented on GitHub (Apr 14, 2026):
Interesting... If you try in a incognito window or after clearing browser data does it change? Could you put the server into debug mode and send some logs both with the key and the user/pass? https://docs.pangolin.net/self-host/advanced/config-file#param-log-level
Okay, the logs do not reveal much, they mainly show that Pangolin is verifying the session Badger sent. However, I was able to narrow the issue down to Badger.
With Badger v1.3.1, login works as expected, while with v1.4.0 it does not.
One interesting observation is that even when running Badger v1.4.0, the logs from badger/pangolin still report the version as v1.3.1.
There is a significant amount of sensitive data in the logs, so I would prefer not to share them publicly.
This issue can be closed on my side, I will open a dedicated issue in the Badger repository.
As a general suggestion, it would be very helpful to have a toggle or option to anonymize logs automatically, so they can be shared safely for debugging purposes.
<!-- gh-comment-id:4252763235 -->
@Blacks-Army commented on GitHub (Apr 15, 2026):
Okay, the logs do not reveal much, they mainly show that Pangolin is verifying the session Badger sent. However, I was able to narrow the issue down to Badger.
With Badger v1.3.1, login works as expected, while with v1.4.0 it does not.
One interesting observation is that even when running Badger v1.4.0, the logs from badger/pangolin still report the version as v1.3.1.
There is a significant amount of sensitive data in the logs, so I would prefer not to share them publicly.
This issue can be closed on my side, I will open a dedicated issue in the Badger repository.
As a general suggestion, it would be very helpful to have a toggle or option to anonymize logs automatically, so they can be shared safely for debugging purposes.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @Blacks-Army on GitHub (Apr 14, 2026).
Original GitHub issue: https://github.com/fosrl/pangolin/issues/2859
Describe the Bug
Hi,
since upgrading Pangolin from 1.17.0 to 1.17.1, I am no longer able to log in. The same setup worked without any issues on version 1.17.0.
What happens:
Environment:
Logs:
Observed behavior:
Expected behavior:
After successful authentication, the user should be logged in and redirected to the dashboard.
Environment
@oschwartz10612 commented on GitHub (Apr 14, 2026):
Interesting... If you try in a incognito window or after clearing browser data does it change? Could you put the server into debug mode and send some logs both with the key and the user/pass? https://docs.pangolin.net/self-host/advanced/config-file#param-log-level
@Blacks-Army commented on GitHub (Apr 15, 2026):
Okay, the logs do not reveal much, they mainly show that Pangolin is verifying the session Badger sent. However, I was able to narrow the issue down to Badger.
With Badger v1.3.1, login works as expected, while with v1.4.0 it does not.
One interesting observation is that even when running Badger v1.4.0, the logs from badger/pangolin still report the version as v1.3.1.
There is a significant amount of sensitive data in the logs, so I would prefer not to share them publicly.
This issue can be closed on my side, I will open a dedicated issue in the Badger repository.
As a general suggestion, it would be very helpful to have a toggle or option to anonymize logs automatically, so they can be shared safely for debugging purposes.