I have a brief question. If my forwarding proxy only knows a users’ name and none of their roles (so cannot supply and x-proxy-roles header), will roles from sg_internal_users and sg_roles_mapping apply?
sg_roles_mapping yes, sg_internal_users is ignored in case of proxy auth