auth: stateless PKCE state, simplify OIDC handlers
- src/lib/auth/oidc-state.ts (new): pack {state, codeVerifier} into a
short-lived signed JWT, store in an httpOnly cookie. Replaces the
process-local Map that broke under multi-worker deployments where
/api/auth/login and /api/auth/callback would land on different workers.
- src/pages/api/auth/{login,callback,logout,profile,status}.ts: drop the
Map-based state-store calls; use oidc-state for set/get/clear.
- src/lib/auth/oidc-client.ts, session-manager.ts, config/authentik.ts:
small adjustments to fit the new state surface.
- src/components/auth/AuthenticatedLayout.astro, src/layouts/Layout.astro:
trim a lot of layout boilerplate (~125 lines each).
- astro.config.mjs, docker-compose.local.yml: minor cleanup.
- authentik-blueprints/heady-oidc.yaml (new): declarative provider +
application blueprint to ship alongside Heady deployments.
This commit is contained in:
parent
0b8812d864
commit
21175c5b7a
14 changed files with 373 additions and 527 deletions
|
|
@ -16,27 +16,11 @@ import {
|
|||
validateAuthentikConfig,
|
||||
} from '../../../lib/config/authentik.js';
|
||||
|
||||
// Force SSR — this route reads env vars and must not be prerendered
|
||||
export const prerender = false;
|
||||
|
||||
export const GET: APIRoute = async ({ url, cookies }) => {
|
||||
try {
|
||||
// During build/prerender, return build-time response
|
||||
if (
|
||||
process.env.NODE_ENV === 'development' &&
|
||||
!process.env.CI &&
|
||||
!process.env.AUTHENTIK_ISSUER
|
||||
) {
|
||||
return new Response(
|
||||
JSON.stringify({
|
||||
service: 'Heady Authentication',
|
||||
status: 'build_mode',
|
||||
message: 'Authentication system available at runtime',
|
||||
timestamp: new Date().toISOString(),
|
||||
}),
|
||||
{
|
||||
status: 200,
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
},
|
||||
);
|
||||
}
|
||||
|
||||
// Load configuration
|
||||
const config = loadAuthentikConfig();
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue