mirror of
https://github.com/Chewbaccalakis/rfid-database.git
synced 2026-09-09 16:01:56 -07:00
Fix OIDC: enable from runtime AUTH_OIDC_* (no NEXT_PUBLIC flag) (#5)
The SSO button required NEXT_PUBLIC_AUTH_OIDC_ENABLED, which is baked at build time and silently fails under Docker runtime env. Drive the login button from server-side AUTH_OIDC_* instead, and document IdP redirect URI + AUTH_URL setup. Co-authored-by: Cursor Agent <[email protected]>
This commit is contained in:
co-authored by
Cursor Agent
parent
0e50c537ee
commit
6d76fecde9
+20
-4
@@ -1,4 +1,10 @@
|
||||
AUTH_SECRET=change-me-to-a-long-random-string
|
||||
|
||||
# Public URL of this app (important behind reverse proxies / Docker)
|
||||
# Example: http://localhost:3000 or https://rfid.example.com
|
||||
# AUTH_URL=http://localhost:3000
|
||||
# AUTH_TRUST_HOST=true
|
||||
|
||||
# Optional: path to SQLite file (default ./data/rfid.db)
|
||||
# RFID_DB_PATH=./data/rfid.db
|
||||
|
||||
@@ -10,10 +16,20 @@ AUTH_SECRET=change-me-to-a-long-random-string
|
||||
# CREATE_USER_PASSWORD=changeme
|
||||
# CREATE_USER_NAME=Admin
|
||||
|
||||
# Optional OIDC (Authentik, Keycloak, Authelia, etc.)
|
||||
# Optional OIDC (Authentik, Keycloak, Authelia, Google, etc.)
|
||||
# Setting these three enables the "Sign in with SSO" button automatically
|
||||
# (no NEXT_PUBLIC_* flag needed).
|
||||
#
|
||||
# In your IdP, create a confidential OIDC client with redirect URI:
|
||||
# {AUTH_URL}/api/auth/callback/oidc
|
||||
# e.g. http://localhost:3000/api/auth/callback/oidc
|
||||
#
|
||||
# AUTH_OIDC_ISSUER must be the issuer that serves
|
||||
# {issuer}/.well-known/openid-configuration
|
||||
# Authentik example: https://sso.example.com/application/o/rfid/
|
||||
# Keycloak example: https://sso.example.com/realms/myrealm
|
||||
#
|
||||
# AUTH_OIDC_ISSUER=https://sso.example.com/application/o/rfid/
|
||||
# AUTH_OIDC_CLIENT_ID=
|
||||
# AUTH_OIDC_CLIENT_SECRET=
|
||||
# AUTH_OIDC_NAME=SSO
|
||||
# NEXT_PUBLIC_AUTH_OIDC_ENABLED=1
|
||||
# NEXT_PUBLIC_AUTH_OIDC_NAME=SSO
|
||||
# AUTH_OIDC_NAME=Authentik
|
||||
|
||||
Reference in New Issue
Block a user