Login page for AUTH_MODE=local instead of the Basic Auth popup
The local mode now shows a login page in the colors of the UI (light/dark theme, FR/EN) with a signed session cookie and the log out button, like the OIDC mode. LOGIN_LOGO shows a PNG mounted in the container on that page. SESSION_TTL applies to both modes (OIDC_SESSION_TTL still works). HTTP Basic credentials are still accepted for scripts. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
ab38a54d54
commit
7aebb1120f
11 files changed
+533
-61
No files matched your search
+7
-3
@@ -4,11 +4,16 @@ HTTP_PORT=8080
|
||||
TZ=Europe/Paris
|
||||
# How long logs are kept (e.g. 7d, 30d, 12w, 1y)
|
||||
RETENTION=30d
|
||||
# Web UI authentication: local (HTTP Basic below, or none) or oidc (OpenID Connect provider)
|
||||
# Web UI authentication: local (login page with the account below, or none) or oidc (OpenID Connect provider)
|
||||
AUTH_MODE=local
|
||||
# local mode: user and password (empty = no authentication)
|
||||
AUTH_USER=
|
||||
AUTH_PASS=
|
||||
# local mode: PNG logo shown on the login page, path inside the container (empty = no logo).
|
||||
# Mount the file in docker-compose.yml, e.g. ./logo.png:/config/logo.png:ro, then LOGIN_LOGO=/config/logo.png
|
||||
LOGIN_LOGO=
|
||||
# Session lifetime, both modes (e.g. 8h, 24h)
|
||||
SESSION_TTL=12h
|
||||
# oidc mode: issuer URL exactly as the provider announces it
|
||||
# (Keycloak: https://sso.example.org/realms/<realm>, Authentik: https://auth.example.org/application/o/<slug>/)
|
||||
OIDC_ISSUER=
|
||||
@@ -16,9 +21,8 @@ OIDC_CLIENT_ID=
|
||||
OIDC_CLIENT_SECRET=
|
||||
# Callback URL of logstream, to register in the provider (path free, /auth/callback recommended)
|
||||
OIDC_REDIRECT_URL=https://logs.example.org/auth/callback
|
||||
# Requested scopes (openid is always added) and session lifetime (e.g. 8h, 24h)
|
||||
# Requested scopes (openid is always added)
|
||||
OIDC_SCOPES=openid profile email
|
||||
OIDC_SESSION_TTL=12h
|
||||
# Reverse DNS: show host names instead of IP addresses (on/off)
|
||||
RDNS=on
|
||||
# DNS server used for reverse lookups (e.g. your router: 192.168.1.1). Empty = system resolver
|
||||
|
||||
Reference in new issue
Block a user