mirror of
https://github.com/Chewbaccalakis/rfid-database.git
synced 2026-09-10 00:11:56 -07:00
Fix Authelia OIDC state check and hide redirect URI on login
Auth.js OIDC defaults to PKCE-only, so no `state` was sent; Authelia rejects that. Enable checks: pkce + state. Remove the public redirect URI hint from the login page.
This commit is contained in:
@@ -6,16 +6,10 @@ import { LoginPageClient } from "@/components/LoginPageClient";
|
|||||||
export const dynamic = "force-dynamic";
|
export const dynamic = "force-dynamic";
|
||||||
|
|
||||||
export default function LoginPage() {
|
export default function LoginPage() {
|
||||||
const authUrl = (process.env.AUTH_URL || "").replace(/\/$/, "");
|
|
||||||
const callbackUrlHint = authUrl
|
|
||||||
? `${authUrl}/api/auth/callback/oidc`
|
|
||||||
: "https://<your-host>/api/auth/callback/oidc";
|
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<LoginPageClient
|
<LoginPageClient
|
||||||
oidcEnabled={isOidcConfigured()}
|
oidcEnabled={isOidcConfigured()}
|
||||||
oidcName={process.env.AUTH_OIDC_NAME || "SSO"}
|
oidcName={process.env.AUTH_OIDC_NAME || "SSO"}
|
||||||
callbackUrlHint={callbackUrlHint}
|
|
||||||
/>
|
/>
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -8,13 +8,11 @@ import { Suspense } from "react";
|
|||||||
type Props = {
|
type Props = {
|
||||||
oidcEnabled: boolean;
|
oidcEnabled: boolean;
|
||||||
oidcName: string;
|
oidcName: string;
|
||||||
callbackUrlHint: string;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
type AuthConfig = {
|
type AuthConfig = {
|
||||||
oidcEnabled: boolean;
|
oidcEnabled: boolean;
|
||||||
oidcName: string;
|
oidcName: string;
|
||||||
callbackUrl: string;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
function authErrorMessage(code: string | null): string | null {
|
function authErrorMessage(code: string | null): string | null {
|
||||||
@@ -36,7 +34,7 @@ function authErrorMessage(code: string | null): string | null {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function LoginForm({ oidcEnabled, oidcName, callbackUrlHint }: Props) {
|
function LoginForm({ oidcEnabled, oidcName }: Props) {
|
||||||
const router = useRouter();
|
const router = useRouter();
|
||||||
const params = useSearchParams();
|
const params = useSearchParams();
|
||||||
const callbackUrl = params.get("callbackUrl") || "/";
|
const callbackUrl = params.get("callbackUrl") || "/";
|
||||||
@@ -62,7 +60,6 @@ function LoginForm({ oidcEnabled, oidcName, callbackUrlHint }: Props) {
|
|||||||
|
|
||||||
const showOidc = runtimeOidc?.oidcEnabled ?? oidcEnabled;
|
const showOidc = runtimeOidc?.oidcEnabled ?? oidcEnabled;
|
||||||
const displayName = runtimeOidc?.oidcName || oidcName;
|
const displayName = runtimeOidc?.oidcName || oidcName;
|
||||||
const redirectHint = runtimeOidc?.callbackUrl || callbackUrlHint;
|
|
||||||
|
|
||||||
async function onSubmit(e: FormEvent) {
|
async function onSubmit(e: FormEvent) {
|
||||||
e.preventDefault();
|
e.preventDefault();
|
||||||
@@ -121,20 +118,13 @@ function LoginForm({ oidcEnabled, oidcName, callbackUrlHint }: Props) {
|
|||||||
{loading ? "Signing in…" : "Sign in"}
|
{loading ? "Signing in…" : "Sign in"}
|
||||||
</button>
|
</button>
|
||||||
{showOidc && (
|
{showOidc && (
|
||||||
<>
|
<button
|
||||||
<button
|
type="button"
|
||||||
type="button"
|
className="btn btn-secondary"
|
||||||
className="btn btn-secondary"
|
onClick={() => signIn("oidc", { callbackUrl })}
|
||||||
onClick={() => signIn("oidc", { callbackUrl })}
|
>
|
||||||
>
|
Sign in with {displayName}
|
||||||
Sign in with {displayName}
|
</button>
|
||||||
</button>
|
|
||||||
<p className="muted" style={{ margin: 0, fontSize: "0.75rem" }}>
|
|
||||||
IdP redirect URI must be exactly:
|
|
||||||
<br />
|
|
||||||
<code className="mono">{redirectHint}</code>
|
|
||||||
</p>
|
|
||||||
</>
|
|
||||||
)}
|
)}
|
||||||
</form>
|
</form>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -45,6 +45,8 @@ function buildProviders(): Provider[] {
|
|||||||
wellKnown: `${issuer}/.well-known/openid-configuration`,
|
wellKnown: `${issuer}/.well-known/openid-configuration`,
|
||||||
clientId: process.env.AUTH_OIDC_CLIENT_ID!,
|
clientId: process.env.AUTH_OIDC_CLIENT_ID!,
|
||||||
clientSecret: process.env.AUTH_OIDC_CLIENT_SECRET!,
|
clientSecret: process.env.AUTH_OIDC_CLIENT_SECRET!,
|
||||||
|
// Auth.js OIDC defaults to PKCE-only; Authelia requires a strong `state`
|
||||||
|
checks: ["pkce", "state"],
|
||||||
authorization: {
|
authorization: {
|
||||||
params: {
|
params: {
|
||||||
scope: "openid email profile",
|
scope: "openid email profile",
|
||||||
|
|||||||
Reference in New Issue
Block a user