mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-07-26 11:49:16 +00:00
6890224903
- Add Host header injection validation for OAuth callback URL derivation when SSO_CALLBACK_URL is not set (extracted into shared getSSOBaseUrl helper) - Add startup warning when OIDC providers are enabled without SSO_CALLBACK_URL - Add diagnostic logging for claim fallback, email changes on re-login, and admin seat limit enforcement (gated behind Developer Mode) - Add Custom OIDC environment variables to .env.example - Fix stale AdmiralGate comment in SSOSection.tsx - Fix .env.example section header referencing removed Admiral tier gate - Fix docs: correct Custom OIDC display name default, replace nonexistent DEBUG=true env var reference with Developer Mode toggle - Add tests for role enforcement (viewer 403), API token scope denial, OIDC claim edge cases, Custom OIDC test connection, callback error params - Refresh SSO settings screenshots
80 lines
2.5 KiB
Bash
80 lines
2.5 KiB
Bash
# Sencho Configuration
|
|
# Copy this file to .env and update the values for production
|
|
|
|
# JWT secret - generate a secure random string for production
|
|
JWT_SECRET=your-secure-jwt-secret-here
|
|
|
|
# Directory containing docker-compose files
|
|
COMPOSE_DIR=/path/to/your/compose/files
|
|
|
|
# HTTP server port (default: 3000)
|
|
PORT=3000
|
|
|
|
# Database and state directory inside the container (default: /app/data)
|
|
DATA_DIR=/app/data
|
|
|
|
# Node environment (set automatically in Docker image; only change for local dev)
|
|
NODE_ENV=production
|
|
|
|
# Frontend URL for CORS in production (leave empty for same-origin setups)
|
|
FRONTEND_URL=
|
|
|
|
# Global API rate limit (requests per minute per user session, production only)
|
|
# Authenticated requests are keyed by user ID; unauthenticated by IP.
|
|
# Internal node-to-node traffic (node_proxy tokens) bypasses this limit entirely.
|
|
API_RATE_LIMIT=200
|
|
|
|
# Polling endpoint rate limit (requests per minute, production only)
|
|
# Applies to dashboard/status polling endpoints that are exempt from the global limit.
|
|
# Increase for environments with many concurrent browser sessions behind shared NAT.
|
|
API_POLLING_RATE_LIMIT=300
|
|
|
|
# ─── SSO / LDAP Configuration ────────────────────────────────────
|
|
|
|
# LDAP / Active Directory
|
|
SSO_LDAP_ENABLED=false
|
|
SSO_LDAP_URL=ldap://ldap.example.com:389
|
|
SSO_LDAP_BIND_DN=cn=readonly,dc=example,dc=com
|
|
SSO_LDAP_BIND_PASSWORD=
|
|
SSO_LDAP_SEARCH_BASE=ou=users,dc=example,dc=com
|
|
SSO_LDAP_SEARCH_FILTER=(uid={{username}})
|
|
SSO_LDAP_ADMIN_GROUP_DN=
|
|
SSO_LDAP_DEFAULT_ROLE=viewer
|
|
SSO_LDAP_DISPLAY_NAME=LDAP
|
|
SSO_LDAP_TLS_REJECT_UNAUTHORIZED=true
|
|
|
|
# Google OIDC
|
|
SSO_OIDC_GOOGLE_ENABLED=false
|
|
SSO_OIDC_GOOGLE_CLIENT_ID=
|
|
SSO_OIDC_GOOGLE_CLIENT_SECRET=
|
|
|
|
# GitHub OAuth
|
|
SSO_OIDC_GITHUB_ENABLED=false
|
|
SSO_OIDC_GITHUB_CLIENT_ID=
|
|
SSO_OIDC_GITHUB_CLIENT_SECRET=
|
|
|
|
# Okta OIDC
|
|
SSO_OIDC_OKTA_ENABLED=false
|
|
SSO_OIDC_OKTA_ISSUER_URL=
|
|
SSO_OIDC_OKTA_CLIENT_ID=
|
|
SSO_OIDC_OKTA_CLIENT_SECRET=
|
|
|
|
# Custom OIDC (Keycloak, Authentik, Authelia, Zitadel, etc.)
|
|
SSO_OIDC_CUSTOM_ENABLED=false
|
|
SSO_OIDC_CUSTOM_DISPLAY_NAME=Custom OIDC
|
|
SSO_OIDC_CUSTOM_ISSUER_URL=
|
|
SSO_OIDC_CUSTOM_CLIENT_ID=
|
|
SSO_OIDC_CUSTOM_CLIENT_SECRET=
|
|
SSO_OIDC_CUSTOM_SCOPES=openid email profile
|
|
SSO_OIDC_CUSTOM_ID_CLAIM=
|
|
SSO_OIDC_CUSTOM_USERNAME_CLAIM=
|
|
SSO_OIDC_CUSTOM_EMAIL_CLAIM=
|
|
|
|
# Role mapping (shared across OIDC providers)
|
|
SSO_OIDC_ADMIN_CLAIM=groups
|
|
SSO_OIDC_ADMIN_CLAIM_VALUE=sencho-admins
|
|
SSO_DEFAULT_ROLE=viewer
|
|
|
|
# External base URL for OAuth callback URLs (required behind reverse proxy)
|
|
SSO_CALLBACK_URL=
|