Two rounds of polish on the single sign-on shipped in 1.90.0:
The identity headers arrived in 1.90.0 — a per-service Pass the signed-in email to the servers toggle sets X-Auth-Request-Email and Remote-User from the verified session, for apps that sign a proxy-identified visitor in themselves (Grafana auth-proxy and friends). Client-sent copies of those headers are deleted on every service, forwarding or not, so the value is always the proxy's own word.
1.90.1 fixes the provider guides: once a real client id was saved, the setup steps suggested it as the authentik provider and application name, the slug, and Google's client name — a generated credential standing where a person picks a label. Names and slugs now suggest haproxy-manager throughout; the saved client id appears only where an admin genuinely chooses one, Authelia's client entry.
Upgrading from 1.90.0: nothing to do. From earlier: SSO sessions re-issue silently on the next visit.
Packages are attached below; the container image is at ghcr.io/avandeputte/haproxy-manager:1.90.1.