2026-10-03, SPICE sign-in via Authentik behind NPM on .69. (1) Trusting X-Forwarded-Proto/Host from 192.168.123.69 only made SPICE compute redirect_uri=https://spice.angelsworks.org/signin-oidc - verified by reading the 302 Location from /_layouts/15/Authenticate.aspx through the proxy, not by reading code. (2) Over plain http on a LAN IP, ASP.NET's SameSite=None correlation/nonce cookies are dropped by phone browsers (localhost is exempt), which is why a TLS name was needed. (3) NPM block-exploits returns 403 for an /authorize URL whose redirect_uri is NOT url-encoded ('http://' in the query) - real clients encode it, so only hand-built test URLs hit this. (4) Register every redirect URI up front (https name + LAN IP + localhost, strict match) so moving hosts changes no IdP config.