# Authorization form must be sent from authorization page

**URL:** <https://discourse.jupyter.org/t/authorization-form-must-be-sent-from-authorization-page/3081>\
**Category:** JupyterHub\
**Created:** [January 19, 2020, 2:02pm UTC](https://discourse.jupyter.org/t/authorization-form-must-be-sent-from-authorization-page/3081 "2020-01-19T14:02:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lapin-Blanc](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/lapin-blanc/32/1477_2.png) [@Lapin-Blanc](https://discourse.jupyter.org/u/Lapin-Blanc)\
**Post date:** [January 19, 2020, 2:02pm UTC](https://discourse.jupyter.org/t/authorization-form-must-be-sent-from-authorization-page/3081/1 "2020-01-19T14:02:12Z")

</div>

I’ve set up Jupyterhub behind an apache reverse proxy, using letsencrypt and following instructions in the official docs → Using a reverse proxy.

It works fine until I try to access a service set up as described in nbgrader doc for jupyterhub multiple courses.

I get the “Authorization form must be sent from authorization page”

Looking at the logs I see that the problem probably comes from a difference between the outter referer scheme (https) and the inner one (http).

> ```
> OAuth POST from https://jupyter.myhost.be/hub/api/oauth2/authorize?client_id=service-progsoir&redirect_uri=%2Fservices%2Fprogsoir%2Foauth_callback&response_type=code&state=eyJ1...ZGVyIn0 != http://jupyter.myhost.be/hub/api/oauth2/authorize?client_id=service-progsoir&redirect_uri=%2Fservices%2Fprogsoir%2Foauth_callback&response_type=code&state=eyJ1...ZGVyIn0
> 
> ```

I’ve tried what is mentionned [there](https://github.com/jupyterhub/jupyterhub/issues/2284#issuecomment-520726144), but without success (https is rewrited to http, but querystring is not rewrited)

Any help is welcome 😄

EDIT : continuing my investigations, I found that new option in JupyterHub 1.1.0 which solved my issue : service.oauth\_no\_confirm. As OAuth authentication is bypassed, the problem doesn’t arise anymore

---

<div class="post-metadata">

**Author:** ![Lapin-Blanc](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/lapin-blanc/32/1477_2.png) [@Lapin-Blanc](https://discourse.jupyter.org/u/Lapin-Blanc)\
**Post date:** [January 22, 2020, 12:59pm UTC](https://discourse.jupyter.org/t/authorization-form-must-be-sent-from-authorization-page/3081/2 "2020-01-22T12:59:15Z")

</div>

I finally found another way to achieve this without having to bypass oauth confirmation.

Based on the apache configuration mentionned [here](https://jupyterhub.readthedocs.io/en/stable/reference/config-proxy.html), I just had to add a RequestHeader edit directive :

```
<Location "/">
    # preserve Host header to avoid cross-origin problems
    ProxyPreserveHost on
    
    # Modify referer to http in case of oauth2 
    RequestHeader edit referer "https://(.*/hub/api/oauth2/.*)" http://$1
    
    # proxy to JupyterHub
    ProxyPass http://127.0.0.1:8000/
    ProxyPassReverse http://127.0.0.1:8000/
</Location>
```
