feat(auth): add generic OIDC and OAuth 2.0 plugins (#1056)

This commit is contained in:
Amayaranjan Das
2026-05-02 11:54:07 +05:30
committed by GitHub
parent fdf407a3e4
commit bf1de55c8d
7 changed files with 450 additions and 3 deletions
+49 -1
View File
@@ -65,4 +65,52 @@ CRON_SECRET="your-secret-key-here"
# SENTRY_AUTH_TOKEN=sentry-auth-token
# GOOGLE_ADSENSE_ACCOUNT=ca-pub-xxxxxxxxxxxxxxxx
# GOOGLE_ADSENSE_ACCOUNT=ca-pub-xxxxxxxxxxxxxxxx
# ==============================================================================
# SSO Authentication Configurations
#
# Why two generic providers (OIDC vs OAuth 2.0)?
# - "OIDC" (OpenID Connect) performs strict cryptographic validation on the
# ID Token (verifying 'aud' matching the client ID, 'iss' matching issuer, etc).
# Use this for standard providers like Google, Auth0, Okta, Keycloak.
# - "OAuth 2.0" bypasses strict OIDC validation. Use this for legacy or
# enterprise systems that do not return OIDC ID Tokens
# ==============================================================================
# Generic OIDC Config (Strict Validation)
# ⚠️ Ensure you add "oidc" to the `providers` array in your prompts.config.ts file
# Callback URL to whitelist: <your-domain>/api/auth/callback/oidc
# AUTH_OIDC_ID="dummy-oidc-client-id"
# AUTH_OIDC_SECRET="dummy-oidc-client-secret"
# AUTH_OIDC_ISSUER="https://oidc.example.com"
# AUTH_OIDC_WELLKNOWN="https://oidc.example.com/.well-known/openid-configuration"
# AUTH_OIDC_SCOPE="openid email profile"
# AUTH_OIDC_NAME="Company OIDC"
# Optional overrides (uncomment to use):
# AUTH_OIDC_LOGO="https://your-domain.com/oidc-logo.png" # Local path or full URL to button image
# AUTH_OIDC_AUTHORIZATION_URL="https://oidc.example.com/authorize"
# AUTH_OIDC_TOKEN_URL="https://oidc.example.com/token"
# AUTH_OIDC_USERINFO_URL="https://oidc.example.com/userinfo"
# AUTH_OIDC_JWKS_URL="https://oidc.example.com/jwks"
# AUTH_OIDC_TOKEN_AUTH_METHOD="client_secret_post" # Allowed values: "client_secret_basic", "client_secret_post", "none"
# AUTH_OIDC_ENABLE_PKCE="true" # PKCE is enabled by default. Set to "false" to disable.
# Generic OAuth 2.0 Config (Loose Validation)
# ⚠️ Ensure you add "oauth" to the `providers` array in your prompts.config.ts file
# Callback URL to whitelist: <your-domain>/api/auth/callback/oauth
# AUTH_OAUTH_ID="dummy-oauth-client-id"
# AUTH_OAUTH_SECRET="dummy-oauth-client-secret"
# AUTH_OAUTH_ISSUER="https://sso.example.com"
# AUTH_OAUTH_WELLKNOWN="https://sso.example.com/.well-known/openid-configuration"
# AUTH_OAUTH_SCOPE="email profile"
# AUTH_OAUTH_NAME="Company SSO"
# Optional overrides (uncomment to use):
# AUTH_OAUTH_LOGO="https://your-domain.com/sso-logo.png" # Local path or full URL to button image
# AUTH_OAUTH_AUTHORIZATION_URL="https://sso.example.com/authorize"
# AUTH_OAUTH_TOKEN_URL="https://sso.example.com/token"
# AUTH_OAUTH_USERINFO_URL="https://sso.example.com/userinfo"
# AUTH_OAUTH_JWKS_URL="https://sso.example.com/jwks"
# AUTH_OAUTH_TOKEN_AUTH_METHOD="client_secret_basic" # Allowed values: "client_secret_basic", "client_secret_post", "none"
# AUTH_OAUTH_ENABLE_PKCE="true" # PKCE is enabled by default. Set to "false" to disable.