chore: align the auth variables with the Auth.js v5 convention
Renames the OIDC settings to AUTH_URL, AUTH_SECRET and AUTH_AUTHENTIK_*, the names Auth.js v5 discovers on its own, which is also what the api_llm_loxi project already runs against this same Authentik instance. Matching it means one fewer thing to translate when comparing the two applications, and no glue code to read the variables manually. Also settles on a single public domain: the panel and the browser reach the application on the same origin, so APP_DOMAIN and AUTH_URL cannot disagree. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd
This commit is contained in:
+23
-15
@@ -6,9 +6,10 @@
|
|||||||
# -----------------------------------------------------------------------------
|
# -----------------------------------------------------------------------------
|
||||||
# Application
|
# Application
|
||||||
# -----------------------------------------------------------------------------
|
# -----------------------------------------------------------------------------
|
||||||
# Nom de domaine public de l'app sur le VPS. Sert à trois choses :
|
# Nom de domaine public de l'app sur le VPS. Un seul domaine sert à la fois
|
||||||
# le callback OIDC, l'URL d'image envoyée à l'écran, et les liens du README.
|
# l'écran et le navigateur : le callback OIDC, l'URL d'image envoyée au panneau
|
||||||
APP_DOMAIN=trmnl.loxi.ch
|
# et les liens du README en dépendent tous. Doit rester cohérent avec AUTH_URL.
|
||||||
|
APP_DOMAIN=horaires.loxi.ch
|
||||||
# Port publié en local (dev). En production, Traefik s'en charge : aucun port publié.
|
# Port publié en local (dev). En production, Traefik s'en charge : aucun port publié.
|
||||||
APP_PORT=3010
|
APP_PORT=3010
|
||||||
APP_BIND=127.0.0.1
|
APP_BIND=127.0.0.1
|
||||||
@@ -28,19 +29,26 @@ TEST_DATABASE_URL=
|
|||||||
# -----------------------------------------------------------------------------
|
# -----------------------------------------------------------------------------
|
||||||
# Authentification — Authentik (OIDC, Authorization Code + PKCE)
|
# Authentification — Authentik (OIDC, Authorization Code + PKCE)
|
||||||
# -----------------------------------------------------------------------------
|
# -----------------------------------------------------------------------------
|
||||||
# Doit correspondre EXACTEMENT à l'`issuer` du document de découverte :
|
# Noms de variables imposés par Auth.js v5, identiques au projet api_llm_loxi :
|
||||||
# https://auth.loxi.ch/application/o/<SLUG>/.well-known/openid-configuration
|
# le provider est découvert automatiquement à partir d'AUTH_AUTHENTIK_*.
|
||||||
AUTHENTIK_ISSUER=https://auth.loxi.ch/application/o/CHANGEME/
|
#
|
||||||
AUTHENTIK_CLIENT_ID=
|
# URI de redirection à déclarer dans Authentik (correspondance stricte) :
|
||||||
AUTHENTIK_CLIENT_SECRET=
|
# <AUTH_URL>/api/auth/callback/authentik
|
||||||
# Groupe Authentik dont les membres sont administrateurs. Les autres utilisateurs
|
AUTH_URL=https://horaires.loxi.ch
|
||||||
# authentifiés sont en lecture seule (rôle `viewer`).
|
|
||||||
AUTHENTIK_ADMIN_GROUP=horaires-admins
|
|
||||||
# URL publique complète de l'app. L'URI de redirection à déclarer dans Authentik est
|
|
||||||
# <NEXTAUTH_URL>/api/auth/callback/authentik
|
|
||||||
NEXTAUTH_URL=https://trmnl.loxi.ch
|
|
||||||
# Générer avec : openssl rand -base64 33
|
# Générer avec : openssl rand -base64 33
|
||||||
NEXTAUTH_SECRET=
|
AUTH_SECRET=
|
||||||
|
|
||||||
|
AUTH_AUTHENTIK_ID=
|
||||||
|
AUTH_AUTHENTIK_SECRET=
|
||||||
|
# Doit correspondre EXACTEMENT à l'`issuer` du document de découverte, slash
|
||||||
|
# final compris :
|
||||||
|
# https://auth.loxi.ch/application/o/<SLUG>/.well-known/openid-configuration
|
||||||
|
AUTH_AUTHENTIK_ISSUER=https://auth.loxi.ch/application/o/horaires-ita-ito/
|
||||||
|
# Libellé du bouton sur la page de connexion.
|
||||||
|
AUTHENTIK_DISPLAY_NAME=Loxi
|
||||||
|
# Groupe Authentik dont les membres sont administrateurs. Tout autre utilisateur
|
||||||
|
# authentifié est en lecture seule (rôle `viewer`).
|
||||||
|
AUTHENTIK_ADMIN_GROUP=horaires-admins
|
||||||
|
|
||||||
# -----------------------------------------------------------------------------
|
# -----------------------------------------------------------------------------
|
||||||
# Écran e-ink — API appareil (BYOS)
|
# Écran e-ink — API appareil (BYOS)
|
||||||
|
|||||||
Reference in New Issue
Block a user