fix: accept multiple OIDC audiences for cross-client auth
- Changed oidc_audience (string) to oidc_audiences (list) - Now accepts tokens with audience: core-api, tatlock-ui, tatlock - Fixes environment endpoint returning "default" user when using tatlock-ui token (audience mismatch was causing JWT claims error) 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.5
parent
c1f16d44e5
commit
6ce34cc016
@@ -91,7 +91,8 @@ class Settings(BaseSettings):
|
||||
# OIDC Authentication (Authentik)
|
||||
oidc_enabled: bool = False
|
||||
oidc_issuer: str = "https://auth.schweitz.net/application/o/core-api/"
|
||||
oidc_audience: str = "core-api"
|
||||
# Accept tokens from multiple clients (core-api, tatlock-ui, tatlock)
|
||||
oidc_audiences: list[str] = ["core-api", "tatlock-ui", "tatlock"]
|
||||
|
||||
# Authentik API (for token validation and user management)
|
||||
authentik_url: str = "https://auth.schweitz.net"
|
||||
|
||||
@@ -24,13 +24,13 @@ def initialize_oidc(settings: Settings) -> None:
|
||||
auth_oidc_config.configure(
|
||||
enabled=settings.oidc_enabled,
|
||||
issuer=settings.oidc_issuer,
|
||||
audience=settings.oidc_audience
|
||||
audiences=settings.oidc_audiences
|
||||
)
|
||||
|
||||
domains_oidc_config.configure(
|
||||
enabled=settings.oidc_enabled,
|
||||
issuer=settings.oidc_issuer,
|
||||
audience=settings.oidc_audience
|
||||
audiences=settings.oidc_audiences
|
||||
)
|
||||
|
||||
if settings.oidc_enabled:
|
||||
|
||||
Reference in New Issue
Block a user