feat(auth): add generic OIDC and OAuth 2.0 plugins (#1056)
This commit is contained in:
+49
-1
@@ -65,4 +65,52 @@ CRON_SECRET="your-secret-key-here"
|
||||
|
||||
# SENTRY_AUTH_TOKEN=sentry-auth-token
|
||||
|
||||
# GOOGLE_ADSENSE_ACCOUNT=ca-pub-xxxxxxxxxxxxxxxx
|
||||
# GOOGLE_ADSENSE_ACCOUNT=ca-pub-xxxxxxxxxxxxxxxx
|
||||
|
||||
# ==============================================================================
|
||||
# SSO Authentication Configurations
|
||||
#
|
||||
# Why two generic providers (OIDC vs OAuth 2.0)?
|
||||
# - "OIDC" (OpenID Connect) performs strict cryptographic validation on the
|
||||
# ID Token (verifying 'aud' matching the client ID, 'iss' matching issuer, etc).
|
||||
# Use this for standard providers like Google, Auth0, Okta, Keycloak.
|
||||
# - "OAuth 2.0" bypasses strict OIDC validation. Use this for legacy or
|
||||
# enterprise systems that do not return OIDC ID Tokens
|
||||
# ==============================================================================
|
||||
|
||||
# Generic OIDC Config (Strict Validation)
|
||||
# ⚠️ Ensure you add "oidc" to the `providers` array in your prompts.config.ts file
|
||||
# Callback URL to whitelist: <your-domain>/api/auth/callback/oidc
|
||||
# AUTH_OIDC_ID="dummy-oidc-client-id"
|
||||
# AUTH_OIDC_SECRET="dummy-oidc-client-secret"
|
||||
# AUTH_OIDC_ISSUER="https://oidc.example.com"
|
||||
# AUTH_OIDC_WELLKNOWN="https://oidc.example.com/.well-known/openid-configuration"
|
||||
# AUTH_OIDC_SCOPE="openid email profile"
|
||||
# AUTH_OIDC_NAME="Company OIDC"
|
||||
# Optional overrides (uncomment to use):
|
||||
# AUTH_OIDC_LOGO="https://your-domain.com/oidc-logo.png" # Local path or full URL to button image
|
||||
# AUTH_OIDC_AUTHORIZATION_URL="https://oidc.example.com/authorize"
|
||||
# AUTH_OIDC_TOKEN_URL="https://oidc.example.com/token"
|
||||
# AUTH_OIDC_USERINFO_URL="https://oidc.example.com/userinfo"
|
||||
# AUTH_OIDC_JWKS_URL="https://oidc.example.com/jwks"
|
||||
# AUTH_OIDC_TOKEN_AUTH_METHOD="client_secret_post" # Allowed values: "client_secret_basic", "client_secret_post", "none"
|
||||
# AUTH_OIDC_ENABLE_PKCE="true" # PKCE is enabled by default. Set to "false" to disable.
|
||||
|
||||
# Generic OAuth 2.0 Config (Loose Validation)
|
||||
# ⚠️ Ensure you add "oauth" to the `providers` array in your prompts.config.ts file
|
||||
# Callback URL to whitelist: <your-domain>/api/auth/callback/oauth
|
||||
# AUTH_OAUTH_ID="dummy-oauth-client-id"
|
||||
# AUTH_OAUTH_SECRET="dummy-oauth-client-secret"
|
||||
# AUTH_OAUTH_ISSUER="https://sso.example.com"
|
||||
# AUTH_OAUTH_WELLKNOWN="https://sso.example.com/.well-known/openid-configuration"
|
||||
# AUTH_OAUTH_SCOPE="email profile"
|
||||
# AUTH_OAUTH_NAME="Company SSO"
|
||||
# Optional overrides (uncomment to use):
|
||||
# AUTH_OAUTH_LOGO="https://your-domain.com/sso-logo.png" # Local path or full URL to button image
|
||||
# AUTH_OAUTH_AUTHORIZATION_URL="https://sso.example.com/authorize"
|
||||
# AUTH_OAUTH_TOKEN_URL="https://sso.example.com/token"
|
||||
# AUTH_OAUTH_USERINFO_URL="https://sso.example.com/userinfo"
|
||||
# AUTH_OAUTH_JWKS_URL="https://sso.example.com/jwks"
|
||||
# AUTH_OAUTH_TOKEN_AUTH_METHOD="client_secret_basic" # Allowed values: "client_secret_basic", "client_secret_post", "none"
|
||||
# AUTH_OAUTH_ENABLE_PKCE="true" # PKCE is enabled by default. Set to "false" to disable.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user