mirror of
https://github.com/Chewbaccalakis/rfid-database.git
synced 2026-09-10 00:11:56 -07:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8ba92654c0 |
@@ -6,10 +6,16 @@ import { LoginPageClient } from "@/components/LoginPageClient";
|
|||||||
export const dynamic = "force-dynamic";
|
export const dynamic = "force-dynamic";
|
||||||
|
|
||||||
export default function LoginPage() {
|
export default function LoginPage() {
|
||||||
|
const authUrl = (process.env.AUTH_URL || "").replace(/\/$/, "");
|
||||||
|
const callbackUrlHint = authUrl
|
||||||
|
? `${authUrl}/api/auth/callback/oidc`
|
||||||
|
: "https://<your-host>/api/auth/callback/oidc";
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<LoginPageClient
|
<LoginPageClient
|
||||||
oidcEnabled={isOidcConfigured()}
|
oidcEnabled={isOidcConfigured()}
|
||||||
oidcName={process.env.AUTH_OIDC_NAME || "SSO"}
|
oidcName={process.env.AUTH_OIDC_NAME || "SSO"}
|
||||||
|
callbackUrlHint={callbackUrlHint}
|
||||||
/>
|
/>
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -8,11 +8,13 @@ import { Suspense } from "react";
|
|||||||
type Props = {
|
type Props = {
|
||||||
oidcEnabled: boolean;
|
oidcEnabled: boolean;
|
||||||
oidcName: string;
|
oidcName: string;
|
||||||
|
callbackUrlHint: string;
|
||||||
};
|
};
|
||||||
|
|
||||||
type AuthConfig = {
|
type AuthConfig = {
|
||||||
oidcEnabled: boolean;
|
oidcEnabled: boolean;
|
||||||
oidcName: string;
|
oidcName: string;
|
||||||
|
callbackUrl: string;
|
||||||
};
|
};
|
||||||
|
|
||||||
function authErrorMessage(code: string | null): string | null {
|
function authErrorMessage(code: string | null): string | null {
|
||||||
@@ -34,7 +36,7 @@ function authErrorMessage(code: string | null): string | null {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function LoginForm({ oidcEnabled, oidcName }: Props) {
|
function LoginForm({ oidcEnabled, oidcName, callbackUrlHint }: Props) {
|
||||||
const router = useRouter();
|
const router = useRouter();
|
||||||
const params = useSearchParams();
|
const params = useSearchParams();
|
||||||
const callbackUrl = params.get("callbackUrl") || "/";
|
const callbackUrl = params.get("callbackUrl") || "/";
|
||||||
@@ -60,6 +62,7 @@ function LoginForm({ oidcEnabled, oidcName }: Props) {
|
|||||||
|
|
||||||
const showOidc = runtimeOidc?.oidcEnabled ?? oidcEnabled;
|
const showOidc = runtimeOidc?.oidcEnabled ?? oidcEnabled;
|
||||||
const displayName = runtimeOidc?.oidcName || oidcName;
|
const displayName = runtimeOidc?.oidcName || oidcName;
|
||||||
|
const redirectHint = runtimeOidc?.callbackUrl || callbackUrlHint;
|
||||||
|
|
||||||
async function onSubmit(e: FormEvent) {
|
async function onSubmit(e: FormEvent) {
|
||||||
e.preventDefault();
|
e.preventDefault();
|
||||||
@@ -118,13 +121,20 @@ function LoginForm({ oidcEnabled, oidcName }: Props) {
|
|||||||
{loading ? "Signing in…" : "Sign in"}
|
{loading ? "Signing in…" : "Sign in"}
|
||||||
</button>
|
</button>
|
||||||
{showOidc && (
|
{showOidc && (
|
||||||
<button
|
<>
|
||||||
type="button"
|
<button
|
||||||
className="btn btn-secondary"
|
type="button"
|
||||||
onClick={() => signIn("oidc", { callbackUrl })}
|
className="btn btn-secondary"
|
||||||
>
|
onClick={() => signIn("oidc", { callbackUrl })}
|
||||||
Sign in with {displayName}
|
>
|
||||||
</button>
|
Sign in with {displayName}
|
||||||
|
</button>
|
||||||
|
<p className="muted" style={{ margin: 0, fontSize: "0.75rem" }}>
|
||||||
|
IdP redirect URI must be exactly:
|
||||||
|
<br />
|
||||||
|
<code className="mono">{redirectHint}</code>
|
||||||
|
</p>
|
||||||
|
</>
|
||||||
)}
|
)}
|
||||||
</form>
|
</form>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -45,8 +45,6 @@ function buildProviders(): Provider[] {
|
|||||||
wellKnown: `${issuer}/.well-known/openid-configuration`,
|
wellKnown: `${issuer}/.well-known/openid-configuration`,
|
||||||
clientId: process.env.AUTH_OIDC_CLIENT_ID!,
|
clientId: process.env.AUTH_OIDC_CLIENT_ID!,
|
||||||
clientSecret: process.env.AUTH_OIDC_CLIENT_SECRET!,
|
clientSecret: process.env.AUTH_OIDC_CLIENT_SECRET!,
|
||||||
// Auth.js OIDC defaults to PKCE-only; Authelia requires a strong `state`
|
|
||||||
checks: ["pkce", "state"],
|
|
||||||
authorization: {
|
authorization: {
|
||||||
params: {
|
params: {
|
||||||
scope: "openid email profile",
|
scope: "openid email profile",
|
||||||
|
|||||||
Reference in New Issue
Block a user