feat: Add generic OIDC authentication provider (#3760)
@@ -94,7 +94,7 @@ AUTH_SECRET_KEY=""
|
||||
######################################
|
||||
|
||||
AUTH_TOKEN_EXPIRE_MINUTES=525600
|
||||
# Possible authorization methods: user-id-only, username-password, nostr-auth-nip98, google-auth, github-auth, keycloak-auth
|
||||
# Possible authorization methods: user-id-only, username-password, nostr-auth-nip98, google-auth, github-auth, keycloak-auth, oidc-auth
|
||||
AUTH_ALLOWED_METHODS="user-id-only, username-password"
|
||||
# Set this flag if HTTP is used for OAuth
|
||||
# OAUTHLIB_INSECURE_TRANSPORT="1"
|
||||
@@ -271,6 +271,50 @@ KEYCLOAK_DISCOVERY_URL=""
|
||||
KEYCLOAK_CLIENT_CUSTOM_ORG=""
|
||||
KEYCLOAK_CLIENT_CUSTOM_ICON=""
|
||||
|
||||
# OIDC OAuth Config
|
||||
# Generic OIDC provider configuration
|
||||
# Make sure that the redirect URI in your OIDC provider is set to: https://{domain}/api/v1/auth/oidc/token
|
||||
# Required scopes: openid, email, profile
|
||||
# The discovery URL must be accessible from your LNbits server
|
||||
# Always use HTTPS in production environments
|
||||
# The CUSTOM_ORG and CUSTOM_ICON settings allow you to customize the login button
|
||||
# For example: "Login via Zitadel" with the Zitadel logo
|
||||
OIDC_DISCOVERY_URL=""
|
||||
OIDC_CLIENT_ID=""
|
||||
OIDC_CLIENT_SECRET=""
|
||||
OIDC_CLIENT_CUSTOM_ORG=""
|
||||
OIDC_CLIENT_CUSTOM_ICON=""
|
||||
|
||||
# Example OIDC configurations for various providers:
|
||||
#
|
||||
# ZITADEL:
|
||||
# OIDC_DISCOVERY_URL=https://login.yourdomain.de/.well-known/openid-configuration
|
||||
# OIDC_CLIENT_ID=your-zitadel-client-id@project-id
|
||||
# OIDC_CLIENT_SECRET=your-zitadel-client-secret
|
||||
# OIDC_CLIENT_CUSTOM_ORG=Zitadel
|
||||
# OIDC_CLIENT_CUSTOM_ICON=/static/images/zitadel.png
|
||||
#
|
||||
# AUTHENTIK:
|
||||
# OIDC_DISCOVERY_URL=https://authentik.yourdomain.com/application/o/lnbits/.well-known/openid-configuration
|
||||
# OIDC_CLIENT_ID=your-authentik-client-id
|
||||
# OIDC_CLIENT_SECRET=your-authentik-client-secret
|
||||
# OIDC_CLIENT_CUSTOM_ORG=Authentik
|
||||
# OIDC_CLIENT_CUSTOM_ICON=/static/images/authentik.png
|
||||
#
|
||||
# AUTHELIA:
|
||||
# OIDC_DISCOVERY_URL=https://auth.yourdomain.com/.well-known/openid-configuration
|
||||
# OIDC_CLIENT_ID=your-authelia-client-id
|
||||
# OIDC_CLIENT_SECRET=your-authelia-client-secret
|
||||
# OIDC_CLIENT_CUSTOM_ORG=Authelia
|
||||
# OIDC_CLIENT_CUSTOM_ICON=/static/images/authelia.png
|
||||
#
|
||||
# OKTA:
|
||||
# OIDC_DISCOVERY_URL=https://your-domain.okta.com/.well-known/openid-configuration
|
||||
# OIDC_CLIENT_ID=your-okta-client-id
|
||||
# OIDC_CLIENT_SECRET=your-okta-client-secret
|
||||
# OIDC_CLIENT_CUSTOM_ORG=Okta
|
||||
# OIDC_CLIENT_CUSTOM_ICON=/static/images/okta.png
|
||||
|
||||
|
||||
######################################
|
||||
|
||||
|
||||
@@ -0,0 +1,139 @@
|
||||
# Generic OIDC Authentication Configuration
|
||||
|
||||
This document explains how to configure generic OIDC authentication for LNbits, which allows integration with various OIDC-compliant authentication providers such as Zitadel, Authentik, and others.
|
||||
|
||||
## Overview
|
||||
|
||||
The generic OIDC provider (`oidc`) complements the existing Keycloak provider and allows you to integrate any OIDC-compliant authentication service. You can customize the login button with your own organization name and icon.
|
||||
|
||||
## Configuration
|
||||
|
||||
Add the following environment variables to your `.env` file or system environment:
|
||||
|
||||
### Required Settings
|
||||
|
||||
```bash
|
||||
# Enable OIDC authentication
|
||||
LNBITS_AUTH_ALLOWED_METHODS=oidc-auth
|
||||
|
||||
# OIDC Discovery URL (well-known endpoint)
|
||||
LNBITS_OIDC_DISCOVERY_URL=https://your-oidc-provider-domain/.well-known/openid-configuration
|
||||
|
||||
# Client credentials from your OIDC provider
|
||||
LNBITS_OIDC_CLIENT_ID=your-client-id
|
||||
LNBITS_OIDC_CLIENT_SECRET=your-client-secret
|
||||
```
|
||||
|
||||
### Optional Settings - Customize the Login Button
|
||||
|
||||
You can customize how the OIDC login button appears to your users:
|
||||
|
||||
```bash
|
||||
# Custom organization name (displayed on the login button)
|
||||
# Example: "Login via Zitadel" or "Login via Authentik"
|
||||
LNBITS_OIDC_CLIENT_CUSTOM_ORG="Zitadel"
|
||||
|
||||
# Custom icon URL (displayed on the login button)
|
||||
# Can be a full URL or a path to a local image
|
||||
LNBITS_OIDC_CLIENT_CUSTOM_ICON=https://zitadel.com/favicon.svg
|
||||
```
|
||||
|
||||
If not set, the button will display "Login via OIDC" with a generic lock icon.
|
||||
|
||||
## Zitadel Configuration Example
|
||||
|
||||
For Zitadel, configure as follows:
|
||||
|
||||
1. Create a new application in Zitadel
|
||||
2. Choose "Web" application type
|
||||
3. Configure the redirect URI: `https://your-lnbits-domain/api/v1/auth/oidc/token`
|
||||
4. Save the Client ID and Client Secret
|
||||
5. Use these environment variables:
|
||||
|
||||
```bash
|
||||
LNBITS_AUTH_ALLOWED_METHODS=oidc-auth
|
||||
LNBITS_OIDC_DISCOVERY_URL=https://your-oidc-provider-domain/.well-known/openid-configuration
|
||||
LNBITS_OIDC_CLIENT_ID=your-zitadel-client-id
|
||||
LNBITS_OIDC_CLIENT_SECRET=your-zitadel-client-secret
|
||||
# Customize the button to show "Login via Zitadel" with Zitadel's logo
|
||||
LNBITS_OIDC_CLIENT_CUSTOM_ORG="Zitadel"
|
||||
LNBITS_OIDC_CLIENT_CUSTOM_ICON="https://zitadel.com/favicon.svg"
|
||||
```
|
||||
|
||||
**Result**: The login page will display a button with the text "Login via Zitadel" and the Zitadel logo.
|
||||
|
||||
## Authentik Configuration Example
|
||||
|
||||
For Authentik:
|
||||
|
||||
1. Create a new OAuth2/OpenID Provider
|
||||
2. Set the redirect URI: `https://your-lnbits-domain/api/v1/auth/oidc/token`
|
||||
3. Configure scopes: `openid`, `email`, `profile`
|
||||
4. Get the Client ID and Client Secret
|
||||
|
||||
```bash
|
||||
LNBITS_AUTH_ALLOWED_METHODS=oidc-auth
|
||||
LNBITS_OIDC_DISCOVERY_URL=https://authentik.yourdomain.com/application/o/your-app/.well-known/openid-configuration
|
||||
LNBITS_OIDC_CLIENT_ID=your-authentik-client-id
|
||||
LNBITS_OIDC_CLIENT_SECRET=your-authentik-client-secret
|
||||
LNBITS_OIDC_CLIENT_CUSTOM_ORG="Authentik"
|
||||
```
|
||||
|
||||
## Multiple Auth Methods
|
||||
|
||||
You can enable multiple authentication methods simultaneously:
|
||||
|
||||
```bash
|
||||
LNBITS_AUTH_ALLOWED_METHODS=username-password,oidc-auth,keycloak-auth
|
||||
```
|
||||
|
||||
## Discovery Endpoint Requirements
|
||||
|
||||
Your OIDC provider must expose a standard discovery endpoint (`.well-known/openid-configuration`) that includes:
|
||||
|
||||
- `authorization_endpoint`
|
||||
- `token_endpoint`
|
||||
- `userinfo_endpoint`
|
||||
- `jwks_uri` (JSON Web Key Set)
|
||||
|
||||
The OIDC implementation will automatically fetch these endpoints from the discovery URL.
|
||||
|
||||
## User Mapping
|
||||
|
||||
The OIDC provider maps user information from the OIDC userinfo endpoint:
|
||||
|
||||
- `sub` → User ID
|
||||
- `email` → Email address
|
||||
- `given_name` → First name
|
||||
- `family_name` → Last name
|
||||
- `name` or `preferred_username` → Display name
|
||||
- `picture` → Profile picture URL
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### Authentication fails
|
||||
|
||||
1. Verify the discovery URL is accessible
|
||||
2. Check that Client ID and Client Secret are correct
|
||||
3. Ensure redirect URI in your OIDC provider matches: `https://your-lnbits-domain/api/v1/auth/oidc/token`
|
||||
4. Check LNbits logs for detailed error messages
|
||||
|
||||
### User info not populated
|
||||
|
||||
Some OIDC providers may use different claim names. If user information is not correctly populated, check your provider's userinfo endpoint response format and adjust the provider class if needed.
|
||||
|
||||
## Security Considerations
|
||||
|
||||
- Always use HTTPS in production
|
||||
- Keep client secrets secure and never commit them to version control
|
||||
- Use environment variables or secure configuration management
|
||||
- Regularly rotate client secrets
|
||||
- Review OIDC provider's security best practices
|
||||
|
||||
## Implementation Details
|
||||
|
||||
The OIDC provider is implemented in `lnbits/core/models/sso/oidc.py` and extends the `fastapi_sso` library's `SSOBase` class. It uses the standard OpenID Connect flow with:
|
||||
|
||||
- Scopes: `openid`, `email`, `profile`
|
||||
- Response type: `code` (authorization code flow)
|
||||
- Discovery document for automatic endpoint resolution
|
||||
@@ -0,0 +1 @@
|
||||
"""SSO authentication providers for LNbits"""
|
||||
@@ -0,0 +1,36 @@
|
||||
"""Generic OIDC SSO Login Helper"""
|
||||
|
||||
from typing import Optional
|
||||
|
||||
import httpx
|
||||
from fastapi_sso.sso.base import DiscoveryDocument, OpenID, SSOBase
|
||||
|
||||
|
||||
class OidcSSO(SSOBase):
|
||||
"""Class providing login via Generic OIDC OAuth (e.g., Zitadel, Authentik, etc.)"""
|
||||
|
||||
provider = "oidc"
|
||||
scope = ["openid", "email", "profile"]
|
||||
discovery_url = ""
|
||||
|
||||
async def openid_from_response(
|
||||
self, response: dict, session: Optional["httpx.AsyncClient"] = None
|
||||
) -> OpenID:
|
||||
"""Return OpenID from user information provided by OIDC provider"""
|
||||
return OpenID(
|
||||
email=response.get("email", ""),
|
||||
provider=self.provider,
|
||||
id=response.get("sub"),
|
||||
first_name=response.get("given_name"),
|
||||
last_name=response.get("family_name"),
|
||||
display_name=response.get("name") or response.get("preferred_username"),
|
||||
picture=response.get("picture"),
|
||||
)
|
||||
|
||||
async def get_discovery_document(self) -> DiscoveryDocument:
|
||||
"""Get document containing handy urls"""
|
||||
async with httpx.AsyncClient() as session:
|
||||
response = await session.get(self.discovery_url)
|
||||
content = response.json()
|
||||
|
||||
return content
|
||||
@@ -796,6 +796,7 @@ class AuthMethods(Enum):
|
||||
google_auth = "google-auth"
|
||||
github_auth = "github-auth"
|
||||
keycloak_auth = "keycloak-auth"
|
||||
oidc_auth = "oidc-auth"
|
||||
|
||||
@classmethod
|
||||
def all(cls):
|
||||
@@ -806,6 +807,7 @@ class AuthMethods(Enum):
|
||||
AuthMethods.google_auth.value,
|
||||
AuthMethods.github_auth.value,
|
||||
AuthMethods.keycloak_auth.value,
|
||||
AuthMethods.oidc_auth.value,
|
||||
]
|
||||
|
||||
|
||||
@@ -851,6 +853,14 @@ class KeycloakAuthSettings(LNbitsSettings):
|
||||
keycloak_client_custom_icon: str | None = Field(default=None)
|
||||
|
||||
|
||||
class OidcAuthSettings(LNbitsSettings):
|
||||
oidc_discovery_url: str = Field(default="")
|
||||
oidc_client_id: str = Field(default="")
|
||||
oidc_client_secret: str = Field(default="")
|
||||
oidc_client_custom_org: str | None = Field(default=None)
|
||||
oidc_client_custom_icon: str | None = Field(default=None)
|
||||
|
||||
|
||||
class AuditSettings(LNbitsSettings):
|
||||
lnbits_audit_enabled: bool = Field(default=True)
|
||||
|
||||
@@ -958,6 +968,7 @@ class EditableSettings(
|
||||
GoogleAuthSettings,
|
||||
GitHubAuthSettings,
|
||||
KeycloakAuthSettings,
|
||||
OidcAuthSettings,
|
||||
):
|
||||
@validator(
|
||||
"lnbits_admin_users",
|
||||
@@ -1174,6 +1185,8 @@ class PublicSettings(BaseModel):
|
||||
auth_methods: list[str] = Field(alias="authMethods")
|
||||
keycloak_org: str | None = Field(alias="keycloakOrg")
|
||||
keycloak_icon: str | None = Field(alias="keycloakIcon")
|
||||
oidc_org: str | None = Field(alias="oidcOrg")
|
||||
oidc_icon: str | None = Field(alias="oidcIcon")
|
||||
has_holdinvoice: bool = Field(alias="hasHoldinvoice")
|
||||
has_nodemanager: bool = Field(alias="hasNodemanager")
|
||||
show_nodemanager: bool = Field(alias="showNodemanager")
|
||||
@@ -1238,6 +1251,8 @@ class PublicSettings(BaseModel):
|
||||
authMethods=settings.auth_allowed_methods,
|
||||
keycloakOrg=settings.keycloak_client_custom_org,
|
||||
keycloakIcon=settings.keycloak_client_custom_icon,
|
||||
oidcOrg=settings.oidc_client_custom_org,
|
||||
oidcIcon=settings.oidc_client_custom_icon,
|
||||
hasHoldinvoice=settings.has_holdinvoice,
|
||||
hasNodemanager=settings.has_nodemanager,
|
||||
showNodemanager=settings.lnbits_node_ui and settings.has_nodemanager,
|
||||
|
||||
@@ -640,6 +640,16 @@ window.localisation.br = {
|
||||
auth_keycloak_ci_hint:
|
||||
'Certifique-se de que a URL de retorno de chamada de autorização esteja definida para https://{domain}/api/v1/auth/keycloak/token',
|
||||
auth_keycloak_cs_label: 'Segredo do Cliente Keycloak',
|
||||
auth_keycloak_custom_org_label: 'Organização Personalizada do Keycloak',
|
||||
auth_keycloak_custom_icon_label: 'Ícone Personalizado do Keycloak (URL)',
|
||||
auth_oidc_label: 'URL de Descoberta do OIDC',
|
||||
auth_oidc_ci_label: 'ID do Cliente OIDC',
|
||||
auth_oidc_ci_hint:
|
||||
'Certifique-se de que a URL de retorno de chamada de autorização esteja definida para https://{domain}/api/v1/auth/oidc/token',
|
||||
auth_oidc_cs_label: 'Segredo do Cliente OIDC',
|
||||
auth_oidc_custom_org_label:
|
||||
'Nome da Organização Personalizada OIDC (ex. Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'Ícone Personalizado do OIDC (URL)',
|
||||
auth_keycloak_custom_org_label: 'Keycloak Custom Organization',
|
||||
auth_keycloak_custom_icon_label: 'Ícone Personalizado do Keycloak (URL)',
|
||||
currency_settings: 'Configurações de Moeda',
|
||||
|
||||
@@ -353,6 +353,15 @@ window.localisation.cn = {
|
||||
auth_keycloak_ci_hint:
|
||||
'确保授权回调URL设置为https://{domain}/api/v1/auth/keycloak/token',
|
||||
auth_keycloak_cs_label: 'Keycloak客户端密钥',
|
||||
auth_keycloak_custom_org_label: 'Keycloak 自定义组织',
|
||||
auth_keycloak_custom_icon_label: 'Keycloak 自定义图标 (URL)',
|
||||
auth_oidc_label: 'OIDC 发现 URL',
|
||||
auth_oidc_ci_label: 'OIDC 客户端 ID',
|
||||
auth_oidc_ci_hint:
|
||||
'确保授权回调URL设置为https://{domain}/api/v1/auth/oidc/token',
|
||||
auth_oidc_cs_label: 'OIDC客户端密钥',
|
||||
auth_oidc_custom_org_label: 'OIDC 自定义组织名称(例如 Zitadel、Authentik)',
|
||||
auth_oidc_custom_icon_label: 'OIDC 自定义图标 (URL)',
|
||||
currency_settings: '货币设置',
|
||||
allowed_currencies: '允许的货币',
|
||||
allowed_currencies_hint: '限制可用法定货币的数量',
|
||||
|
||||
@@ -367,6 +367,16 @@ window.localisation.cs = {
|
||||
auth_keycloak_ci_hint:
|
||||
'Ujistěte se, že je autorizace callback URL nastavena na https://{domain}/api/v1/auth/keycloak/token',
|
||||
auth_keycloak_cs_label: 'Klíč k aplikaci Keycloak tajemství',
|
||||
auth_keycloak_custom_org_label: 'Vlastní organizace Keycloak',
|
||||
auth_keycloak_custom_icon_label: 'Vlastní ikona Keycloak (URL)',
|
||||
auth_oidc_label: 'URL pro zjištění OIDC',
|
||||
auth_oidc_ci_label: 'ID klienta OIDC',
|
||||
auth_oidc_ci_hint:
|
||||
'Ujistěte se, že je autorizace callback URL nastavena na https://{domain}/api/v1/auth/oidc/token',
|
||||
auth_oidc_cs_label: 'Klíč k aplikaci OIDC tajemství',
|
||||
auth_oidc_custom_org_label:
|
||||
'Název vlastní organizace OIDC (např. Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'Vlastní ikona OIDC (URL)',
|
||||
currency_settings: 'Nastavení měny',
|
||||
allowed_currencies: 'Povolené měny',
|
||||
allowed_currencies_hint: 'Omezte počet dostupných fiat měn',
|
||||
|
||||
@@ -377,6 +377,16 @@ window.localisation.de = {
|
||||
auth_keycloak_ci_hint:
|
||||
'Stellen Sie sicher, dass die Autorisierungs-Callback-URL auf https://{domain}/api/v1/auth/keycloak/token eingestellt ist.',
|
||||
auth_keycloak_cs_label: 'Keycloak-Client-Geheimnis',
|
||||
auth_keycloak_custom_org_label: 'Keycloak Benutzerdefinierte Organisation',
|
||||
auth_keycloak_custom_icon_label: 'Keycloak Benutzerdefiniertes Symbol (URL)',
|
||||
auth_oidc_label: 'OIDC Discovery-URL',
|
||||
auth_oidc_ci_label: 'OIDC-Client-ID',
|
||||
auth_oidc_ci_hint:
|
||||
'Stellen Sie sicher, dass die Autorisierungs-Callback-URL auf https://{domain}/api/v1/auth/oidc/token eingestellt ist.',
|
||||
auth_oidc_cs_label: 'OIDC-Client-Geheimnis',
|
||||
auth_oidc_custom_org_label:
|
||||
'OIDC Benutzerdefinierter Organisationsname (z.B. Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'OIDC Benutzerdefiniertes Symbol (URL)',
|
||||
currency_settings: 'Währungseinstellungen',
|
||||
allowed_currencies: 'Erlaubte Währungen',
|
||||
allowed_currencies_hint:
|
||||
|
||||
@@ -642,6 +642,14 @@ window.localisation.en = {
|
||||
auth_keycloak_cs_label: 'Keycloak Client Secret',
|
||||
auth_keycloak_custom_org_label: 'Keycloak Custom Organization',
|
||||
auth_keycloak_custom_icon_label: 'Keycloak Custom Icon (URL)',
|
||||
auth_oidc_label: 'OIDC Discovery URL',
|
||||
auth_oidc_ci_label: 'OIDC Client ID',
|
||||
auth_oidc_ci_hint:
|
||||
'Make sure that the authorization callback URL is set to https://{domain}/api/v1/auth/oidc/token',
|
||||
auth_oidc_cs_label: 'OIDC Client Secret',
|
||||
auth_oidc_custom_org_label:
|
||||
'OIDC Custom Organization Name (e.g., Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'OIDC Custom Icon (URL)',
|
||||
currency_settings: 'Currency Settings',
|
||||
allowed_currencies: 'Allowed Currencies',
|
||||
allowed_currencies_hint:
|
||||
|
||||
@@ -379,6 +379,16 @@ window.localisation.es = {
|
||||
auth_keycloak_ci_hint:
|
||||
'Asegúrate de que la URL de devolución de llamada de autorización esté configurada en https://{domain}/api/v1/auth/keycloak/token',
|
||||
auth_keycloak_cs_label: 'Secreto del Cliente de Keycloak',
|
||||
auth_keycloak_custom_org_label: 'Organización personalizada de Keycloak',
|
||||
auth_keycloak_custom_icon_label: 'Icono personalizado de Keycloak (URL)',
|
||||
auth_oidc_label: 'URL de descubrimiento de OIDC',
|
||||
auth_oidc_ci_label: 'ID de cliente de OIDC',
|
||||
auth_oidc_ci_hint:
|
||||
'Asegúrate de que la URL de devolución de llamada de autorización esté configurada en https://{domain}/api/v1/auth/oidc/token',
|
||||
auth_oidc_cs_label: 'Secreto del Cliente de OIDC',
|
||||
auth_oidc_custom_org_label:
|
||||
'Nombre de organización personalizada OIDC (ej. Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'Icono personalizado de OIDC (URL)',
|
||||
currency_settings: 'Configuración de moneda',
|
||||
allowed_currencies: 'Monedas permitidas',
|
||||
allowed_currencies_hint:
|
||||
|
||||
@@ -520,6 +520,14 @@ window.localisation.fi = {
|
||||
auth_keycloak_cs_label: 'Keycloak-asiakassalasana',
|
||||
auth_keycloak_custom_org_label: 'Valinnainen Keycloak-organisaatio',
|
||||
auth_keycloak_custom_icon_label: 'Valinnainen Keycloak-kuvake (URL)',
|
||||
auth_oidc_label: 'OIDC-discovery-URL',
|
||||
auth_oidc_ci_label: 'OIDC-asiakastunnus',
|
||||
auth_oidc_ci_hint:
|
||||
'Varmista, että valtuutuksen palautus-URL on asetettu muotoon https://{domain}/api/v1/auth/oidc/token',
|
||||
auth_oidc_cs_label: 'OIDC-asiakassalasana',
|
||||
auth_oidc_custom_org_label:
|
||||
'OIDC mukautetun organisaation nimi (esim. Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'Valinnainen OIDC-kuvake (URL)',
|
||||
currency_settings: 'Valuutta-asetukset',
|
||||
allowed_currencies: 'Käytettävät valuutat',
|
||||
allowed_currencies_hint: 'Valitse käytettävissä olevat fiat-valuutat',
|
||||
|
||||
@@ -381,6 +381,16 @@ window.localisation.fr = {
|
||||
auth_keycloak_ci_hint:
|
||||
"Assurez-vous que l'URL de rappel d'autorisation est définie sur https://{domain}/api/v1/auth/keycloak/token",
|
||||
auth_keycloak_cs_label: 'Secret client Keycloak',
|
||||
auth_keycloak_custom_org_label: 'Organisation personnalisée Keycloak',
|
||||
auth_keycloak_custom_icon_label: 'Icône personnalisée Keycloak (URL)',
|
||||
auth_oidc_label: 'URL de découverte OIDC',
|
||||
auth_oidc_ci_label: 'ID Client OIDC',
|
||||
auth_oidc_ci_hint:
|
||||
"Assurez-vous que l'URL de rappel d'autorisation est définie sur https://{domain}/api/v1/auth/oidc/token",
|
||||
auth_oidc_cs_label: 'Secret client OIDC',
|
||||
auth_oidc_custom_org_label:
|
||||
"Nom de l'organisation personnalisée OIDC (par ex. Zitadel, Authentik)",
|
||||
auth_oidc_custom_icon_label: 'Icône personnalisée OIDC (URL)',
|
||||
currency_settings: 'Paramètres de devise',
|
||||
allowed_currencies: 'Devises autorisées',
|
||||
allowed_currencies_hint:
|
||||
|
||||
@@ -378,6 +378,16 @@ window.localisation.it = {
|
||||
auth_keycloak_ci_hint:
|
||||
"Assicurati che l'URL di callback dell'autorizzazione sia impostato su https://{domain}/api/v1/auth/keycloak/token",
|
||||
auth_keycloak_cs_label: 'Keycloak Client Secret',
|
||||
auth_keycloak_custom_org_label: 'Organizzazione personalizzata di Keycloak',
|
||||
auth_keycloak_custom_icon_label: 'Icona personalizzata di Keycloak (URL)',
|
||||
auth_oidc_label: 'URL di individuazione di OIDC',
|
||||
auth_oidc_ci_label: 'ID client di OIDC',
|
||||
auth_oidc_ci_hint:
|
||||
"Assicurati che l'URL di callback dell'autorizzazione sia impostato su https://{domain}/api/v1/auth/oidc/token",
|
||||
auth_oidc_cs_label: 'OIDC Client Secret',
|
||||
auth_oidc_custom_org_label:
|
||||
'Nome organizzazione personalizzata OIDC (es. Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'Icona personalizzata di OIDC (URL)',
|
||||
currency_settings: 'Impostazioni valuta',
|
||||
allowed_currencies: 'Valute consentite',
|
||||
allowed_currencies_hint: 'Limita il numero di valute fiat disponibili',
|
||||
|
||||
@@ -369,6 +369,15 @@ window.localisation.jp = {
|
||||
auth_keycloak_ci_hint:
|
||||
'認証コールバックURLが https://{domain}/api/v1/auth/keycloak/token に設定されていることを確認してください。',
|
||||
auth_keycloak_cs_label: 'キークローククライアントシークレット',
|
||||
auth_keycloak_custom_org_label: 'Keycloak カスタム組織',
|
||||
auth_keycloak_custom_icon_label: 'Keycloak カスタムアイコン (URL)',
|
||||
auth_oidc_label: 'OIDC ディスカバリー URL',
|
||||
auth_oidc_ci_label: 'OIDC クライアント ID',
|
||||
auth_oidc_ci_hint:
|
||||
'認証コールバックURLが https://{domain}/api/v1/auth/oidc/token に設定されていることを確認してください。',
|
||||
auth_oidc_cs_label: 'OIDC クライアントシークレット',
|
||||
auth_oidc_custom_org_label: 'OIDC カスタム組織名(例:Zitadel、Authentik)',
|
||||
auth_oidc_custom_icon_label: 'OIDC カスタムアイコン (URL)',
|
||||
currency_settings: '通貨設定',
|
||||
allowed_currencies: '許可されている通貨',
|
||||
allowed_currencies_hint: '利用可能な法定通貨の数を制限する',
|
||||
|
||||
@@ -365,6 +365,16 @@ window.localisation.kr = {
|
||||
auth_keycloak_ci_hint:
|
||||
'승인 콜백 URL이 https://{domain}/api/v1/auth/keycloak/token으로 설정되어 있는지 확인하십시오.',
|
||||
auth_keycloak_cs_label: 'Keycloak 클라이언트 시크릿',
|
||||
auth_keycloak_custom_org_label: 'Keycloak 사용자 정의 조직',
|
||||
auth_keycloak_custom_icon_label: 'Keycloak 사용자 정의 아이콘 (URL)',
|
||||
auth_oidc_label: 'OIDC 디스커버리 URL',
|
||||
auth_oidc_ci_label: 'OIDC 클라이언트 ID',
|
||||
auth_oidc_ci_hint:
|
||||
'승인 콜백 URL이 https://{domain}/api/v1/auth/oidc/token으로 설정되어 있는지 확인하십시오.',
|
||||
auth_oidc_cs_label: 'OIDC 클라이언트 시크릿',
|
||||
auth_oidc_custom_org_label:
|
||||
'OIDC 사용자 정의 조직 이름 (예: Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'OIDC 사용자 정의 아이콘 (URL)',
|
||||
currency_settings: '통화 설정',
|
||||
allowed_currencies: '허용되는 통화',
|
||||
allowed_currencies_hint: '사용 가능한 법정 화폐의 수를 제한하십시오.',
|
||||
|
||||
@@ -377,6 +377,16 @@ window.localisation.nl = {
|
||||
auth_keycloak_ci_hint:
|
||||
'Zorg ervoor dat de autorisatie callback-URL is ingesteld op https://{domain}/api/v1/auth/keycloak/token',
|
||||
auth_keycloak_cs_label: 'Keycloak Clientgeheim',
|
||||
auth_keycloak_custom_org_label: 'Keycloak Aangepaste Organisatie',
|
||||
auth_keycloak_custom_icon_label: 'Keycloak Aangepast Pictogram (URL)',
|
||||
auth_oidc_label: 'OIDC Ontdekking URL',
|
||||
auth_oidc_ci_label: 'OIDC-client-ID',
|
||||
auth_oidc_ci_hint:
|
||||
'Zorg ervoor dat de autorisatie callback-URL is ingesteld op https://{domain}/api/v1/auth/oidc/token',
|
||||
auth_oidc_cs_label: 'OIDC Clientgeheim',
|
||||
auth_oidc_custom_org_label:
|
||||
'OIDC Aangepaste Organisatienaam (bijv. Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'OIDC Aangepast Pictogram (URL)',
|
||||
currency_settings: 'Valuta-instellingen',
|
||||
allowed_currencies: "Toegestane valuta's",
|
||||
allowed_currencies_hint: "Beperk het aantal beschikbare fiatvaluta's",
|
||||
|
||||
@@ -371,6 +371,16 @@ window.localisation.pi = {
|
||||
auth_keycloak_ci_hint:
|
||||
"Make sure thant th' authorization callback URL be set t' https://{domain}/api/v1/auth/keycloak/token",
|
||||
auth_keycloak_cs_label: 'Keycloak Client Secret',
|
||||
auth_keycloak_custom_org_label: 'Keycloak Custom Organization',
|
||||
auth_keycloak_custom_icon_label: 'Keycloak Custom Icon (URL)',
|
||||
auth_oidc_label: 'OIDC Discovery URL',
|
||||
auth_oidc_ci_label: 'OIDC Client ID',
|
||||
auth_oidc_ci_hint:
|
||||
"Make sure thant th' authorization callback URL be set t' https://{domain}/api/v1/auth/oidc/token",
|
||||
auth_oidc_cs_label: 'OIDC Client Secret',
|
||||
auth_oidc_custom_org_label:
|
||||
'OIDC Custom Organization Name (e.g., Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'OIDC Custom Icon (URL)',
|
||||
currency_settings: "Doubloon Settin's",
|
||||
allowed_currencies: "Allo'ed Doubloons",
|
||||
allowed_currencies_hint: 'Limit the number of available fiat doubloons',
|
||||
|
||||
@@ -372,6 +372,16 @@ window.localisation.pl = {
|
||||
auth_keycloak_ci_hint:
|
||||
'Upewnij się, że URL zwrotu autoryzacji jest ustawiony na https://{domain}/api/v1/auth/keycloak/token',
|
||||
auth_keycloak_cs_label: 'Hasło klienta Keycloak',
|
||||
auth_keycloak_custom_org_label: 'Własna organizacja Keycloak',
|
||||
auth_keycloak_custom_icon_label: 'Własna ikona Keycloak (URL)',
|
||||
auth_oidc_label: 'Adres URL Discovery OIDC',
|
||||
auth_oidc_ci_label: 'Identyfikator klienta OIDC',
|
||||
auth_oidc_ci_hint:
|
||||
'Upewnij się, że URL zwrotu autoryzacji jest ustawiony na https://{domain}/api/v1/auth/oidc/token',
|
||||
auth_oidc_cs_label: 'Hasło klienta OIDC',
|
||||
auth_oidc_custom_org_label:
|
||||
'Nazwa własnej organizacji OIDC (np. Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'Własna ikona OIDC (URL)',
|
||||
currency_settings: 'Ustawienia waluty',
|
||||
allowed_currencies: 'Dozwolone waluty',
|
||||
allowed_currencies_hint: 'Ogranicz liczbę dostępnych walut fiducjarnych',
|
||||
|
||||
@@ -375,6 +375,16 @@ window.localisation.pt = {
|
||||
auth_keycloak_ci_hint:
|
||||
'Certifique-se de que o URL de retorno de chamada de autorização esteja definido como https://{domain}/api/v1/auth/keycloak/token',
|
||||
auth_keycloak_cs_label: 'Segredo do Cliente do Keycloak',
|
||||
auth_keycloak_custom_org_label: 'Organização Personalizada do Keycloak',
|
||||
auth_keycloak_custom_icon_label: 'Ícone Personalizado do Keycloak (URL)',
|
||||
auth_oidc_label: 'URL de Descoberta do OIDC',
|
||||
auth_oidc_ci_label: 'ID do Cliente do OIDC',
|
||||
auth_oidc_ci_hint:
|
||||
'Certifique-se de que o URL de retorno de chamada de autorização esteja definido como https://{domain}/api/v1/auth/oidc/token',
|
||||
auth_oidc_cs_label: 'Segredo do Cliente do OIDC',
|
||||
auth_oidc_custom_org_label:
|
||||
'Nome da Organização Personalizada OIDC (ex. Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'Ícone Personalizado do OIDC (URL)',
|
||||
currency_settings: 'Configurações de Moeda',
|
||||
allowed_currencies: 'Moedas Permitidas',
|
||||
allowed_currencies_hint: 'Limite o número de moedas fiduciárias disponíveis',
|
||||
|
||||
@@ -371,6 +371,16 @@ window.localisation.sk = {
|
||||
auth_keycloak_ci_hint:
|
||||
'Uistite sa, že URL spätného volania autorizácie je nastavená na https://{domain}/api/v1/auth/keycloak/token',
|
||||
auth_keycloak_cs_label: 'Tajný kľúč klienta Keycloak',
|
||||
auth_keycloak_custom_org_label: 'Vlastná organizácia Keycloak',
|
||||
auth_keycloak_custom_icon_label: 'Vlastná ikona Keycloak (URL)',
|
||||
auth_oidc_label: 'URL zistenia OIDC',
|
||||
auth_oidc_ci_label: 'ID klienta OIDC',
|
||||
auth_oidc_ci_hint:
|
||||
'Uistite sa, že URL spätného volania autorizácie je nastavená na https://{domain}/api/v1/auth/oidc/token',
|
||||
auth_oidc_cs_label: 'Tajný kľúč klienta OIDC',
|
||||
auth_oidc_custom_org_label:
|
||||
'Názov vlastnej organizácie OIDC (napr. Zitadel, Authentik)',
|
||||
auth_oidc_custom_icon_label: 'Vlastná ikona OIDC (URL)',
|
||||
currency_settings: 'Nastavenia meny',
|
||||
allowed_currencies: 'Povolené meny',
|
||||
allowed_currencies_hint: 'Obmedzte počet dostupných fiat mien',
|
||||
|
||||
@@ -370,6 +370,16 @@ window.localisation.we = {
|
||||
auth_keycloak_ci_hint:
|
||||
"Gwnewch yn siŵr bod URL adalw awdurdodiad wedi'i osod i https://{domain}/api/v1/auth/keycloak/token",
|
||||
auth_keycloak_cs_label: 'Cyfrinach Cleient Keycloak',
|
||||
auth_keycloak_custom_org_label: "Sefydliad Wedi'i Addasu Keycloak",
|
||||
auth_keycloak_custom_icon_label: "Eicon Wedi'i Addasu Keycloak (URL)",
|
||||
auth_oidc_label: 'URL Darganfod OIDC',
|
||||
auth_oidc_ci_label: 'ID Cleient OIDC',
|
||||
auth_oidc_ci_hint:
|
||||
"Gwnewch yn siŵr bod URL adalw awdurdodiad wedi'i osod i https://{domain}/api/v1/auth/oidc/token",
|
||||
auth_oidc_cs_label: 'Cyfrinach Cleient OIDC',
|
||||
auth_oidc_custom_org_label:
|
||||
"Enw Sefydliad Wedi'i Addasu OIDC (e.e. Zitadel, Authentik)",
|
||||
auth_oidc_custom_icon_label: "Eicon Wedi'i Addasu OIDC (URL)",
|
||||
currency_settings: 'Gosodiadau Arian Cyfred',
|
||||
allowed_currencies: 'Ariannau a Ganiateir',
|
||||
allowed_currencies_hint: 'Cyfyngu nifer yr arian cyfred fiat sydd ar gael',
|
||||
|
||||
|
After Width: | Height: | Size: 41 KiB |
|
After Width: | Height: | Size: 14 KiB |
@@ -0,0 +1,19 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 100 100" width="100" height="100">
|
||||
<!-- Background circle -->
|
||||
<circle cx="50" cy="50" r="48" fill="#4A90E2" stroke="#2E5F8E" stroke-width="2"/>
|
||||
|
||||
<!-- Lock body -->
|
||||
<rect x="35" y="45" width="30" height="25" rx="2" fill="#FFFFFF"/>
|
||||
|
||||
<!-- Lock shackle -->
|
||||
<path d="M 40 45 L 40 35 Q 40 25 50 25 Q 60 25 60 35 L 60 45"
|
||||
fill="none" stroke="#FFFFFF" stroke-width="4" stroke-linecap="round"/>
|
||||
|
||||
<!-- Keyhole -->
|
||||
<circle cx="50" cy="55" r="3" fill="#4A90E2"/>
|
||||
<rect x="48.5" y="55" width="3" height="8" fill="#4A90E2"/>
|
||||
|
||||
<!-- ID letters -->
|
||||
<text x="50" y="85" font-family="Arial, sans-serif" font-size="12" font-weight="bold"
|
||||
fill="#FFFFFF" text-anchor="middle">ID</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 773 B |
|
After Width: | Height: | Size: 31 KiB |
|
After Width: | Height: | Size: 26 KiB |
|
After Width: | Height: | Size: 20 KiB |
|
After Width: | Height: | Size: 23 KiB |
@@ -442,7 +442,8 @@ window.app.component('username-password', {
|
||||
'nostr-auth-nip98',
|
||||
'google-auth',
|
||||
'github-auth',
|
||||
'keycloak-auth'
|
||||
'keycloak-auth',
|
||||
'oidc-auth'
|
||||
],
|
||||
username: this.userName,
|
||||
password: this.password_1,
|
||||
|
||||
@@ -1050,6 +1050,34 @@ include('components/lnbits-error.vue') %}
|
||||
></span>
|
||||
</div>
|
||||
</q-btn>
|
||||
<q-btn
|
||||
v-if="authMethods.includes('oidc-auth')"
|
||||
href="/api/v1/auth/oidc"
|
||||
type="a"
|
||||
outline
|
||||
no-caps
|
||||
color="grey"
|
||||
class="btn-fixed-width"
|
||||
>
|
||||
<q-avatar size="32px" class="q-mr-md">
|
||||
<q-img
|
||||
:src="
|
||||
g.settings.oidcIcon
|
||||
? g.settings.oidcIcon
|
||||
: utils.url_for('lnbits/static/images/generic-oidc-logo.svg')
|
||||
"
|
||||
></q-img>
|
||||
</q-avatar>
|
||||
<div>
|
||||
<span
|
||||
v-text="
|
||||
$t('signin_with_custom_org', {
|
||||
custom_org: g.settings.oidcOrg || 'OIDC'
|
||||
})
|
||||
"
|
||||
></span>
|
||||
</div>
|
||||
</q-btn>
|
||||
</div>
|
||||
</q-card-section>
|
||||
</template>
|
||||
|
||||
@@ -192,6 +192,57 @@
|
||||
</div>
|
||||
</div>
|
||||
</q-card-section>
|
||||
<q-card-section
|
||||
v-if="formData.auth_allowed_methods?.includes('oidc-auth')"
|
||||
class="q-pl-xl"
|
||||
>
|
||||
<strong class="q-my-none q-mb-sm">OIDC Auth</strong>
|
||||
|
||||
<div class="row q-col-gutter-sm q-col-gutter-y-md">
|
||||
<div class="col-12 col-md-4">
|
||||
<q-input
|
||||
filled
|
||||
v-model="formData.oidc_discovery_url"
|
||||
:label="$t('auth_oidc_label')"
|
||||
>
|
||||
</q-input>
|
||||
</div>
|
||||
<div class="col-12 col-md-4">
|
||||
<q-input
|
||||
filled
|
||||
v-model="formData.oidc_client_id"
|
||||
:label="$t('auth_oidc_ci_label')"
|
||||
:hint="$t('auth_oidc_ci_hint')"
|
||||
>
|
||||
</q-input>
|
||||
</div>
|
||||
<div class="col-12 col-md-4">
|
||||
<q-input
|
||||
filled
|
||||
v-model="formData.oidc_client_secret"
|
||||
type="password"
|
||||
:label="$t('auth_oidc_cs_label')"
|
||||
>
|
||||
</q-input>
|
||||
</div>
|
||||
<div class="col-12 col-md-4">
|
||||
<q-input
|
||||
filled
|
||||
v-model="formData.oidc_client_custom_org"
|
||||
:label="$t('auth_oidc_custom_org_label')"
|
||||
>
|
||||
</q-input>
|
||||
</div>
|
||||
<div class="col-12 col-md-8">
|
||||
<q-input
|
||||
filled
|
||||
v-model="formData.oidc_client_custom_icon"
|
||||
:label="$t('auth_oidc_custom_icon_label')"
|
||||
>
|
||||
</q-input>
|
||||
</div>
|
||||
</div>
|
||||
</q-card-section>
|
||||
<q-separator></q-separator>
|
||||
<q-card-section class="q-pa-none">
|
||||
<br />
|
||||
|
||||
@@ -262,7 +262,9 @@
|
||||
<div
|
||||
v-if="
|
||||
'google-auth' in g.settings.authMethods ||
|
||||
'github-auth' in g.settings.authMethods
|
||||
'github-auth' in g.settings.authMethods ||
|
||||
'keycloak-auth' in g.settings.authMethods ||
|
||||
'oidc-auth' in g.settings.authMethods
|
||||
"
|
||||
class="col q-pa-sm text-h6"
|
||||
>
|
||||
@@ -310,6 +312,58 @@
|
||||
<div>GitHub</div>
|
||||
</q-btn>
|
||||
</div>
|
||||
<div
|
||||
v-if="'keycloak-auth' in g.settings.authMethods"
|
||||
class="col q-pa-sm"
|
||||
>
|
||||
<q-btn
|
||||
:href="`/api/v1/auth/keycloak?user_id=${g.user.id}`"
|
||||
type="a"
|
||||
outline
|
||||
no-caps
|
||||
color="grey"
|
||||
rounded
|
||||
class="full-width"
|
||||
>
|
||||
<q-avatar size="32px" class="q-mr-md">
|
||||
<q-img
|
||||
:src="
|
||||
g.settings.keycloakIcon
|
||||
? g.settings.keycloakIcon
|
||||
: '{{ static_url_for('static', 'images/keycloak-logo.png') }}'
|
||||
"
|
||||
></q-img>
|
||||
</q-avatar>
|
||||
<div
|
||||
v-text="g.settings.keycloakOrg || 'Keycloak'"
|
||||
></div>
|
||||
</q-btn>
|
||||
</div>
|
||||
<div
|
||||
v-if="'oidc-auth' in g.settings.authMethods"
|
||||
class="col q-pa-sm"
|
||||
>
|
||||
<q-btn
|
||||
:href="`/api/v1/auth/oidc?user_id=${g.user.id}`"
|
||||
type="a"
|
||||
outline
|
||||
no-caps
|
||||
color="grey"
|
||||
rounded
|
||||
class="full-width"
|
||||
>
|
||||
<q-avatar size="32px" class="q-mr-md">
|
||||
<q-img
|
||||
:src="
|
||||
g.settings.oidcIcon
|
||||
? g.settings.oidcIcon
|
||||
: '{{ static_url_for('static', 'images/generic-oidc-logo.svg') }}'
|
||||
"
|
||||
></q-img>
|
||||
</q-avatar>
|
||||
<div v-text="g.settings.oidcOrg || 'OIDC'"></div>
|
||||
</q-btn>
|
||||
</div>
|
||||
</div>
|
||||
</q-card-section>
|
||||
|
||||
|
||||