OpenID Connect login (AUTH_MODE=oidc)

AUTH_MODE=local keeps the HTTP Basic authentication (unchanged default);
AUTH_MODE=oidc logs in through an OpenID Connect provider with the
authorization code flow and PKCE, standard library only: discovery,
ID token signature (RS/PS/ES) and claims checks, signed session cookie
whose key is kept in DATA_DIR. The UI gets a log out button and reloads
into the login when the session ends.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
cedricandClaude Opus 5.5 committed 2026-10-03 10:39:54 +02:00
1 parent 84f8b9f9ad
commit f30c353b46
9 files changed
+1013 -37

No files matched your search

+13 -1
View File
@@ -4,9 +4,21 @@ HTTP_PORT=8080
TZ=Europe/Paris
# How long logs are kept (e.g. 7d, 30d, 12w, 1y)
RETENTION=30d
# Web UI authentication (empty = disabled)
# Web UI authentication: local (HTTP Basic below, or none) or oidc (OpenID Connect provider)
AUTH_MODE=local
# local mode: user and password (empty = no authentication)
AUTH_USER=
AUTH_PASS=
# oidc mode: issuer URL exactly as the provider announces it
# (Keycloak: https://sso.example.org/realms/<realm>, Authentik: https://auth.example.org/application/o/<slug>/)
OIDC_ISSUER=
OIDC_CLIENT_ID=
OIDC_CLIENT_SECRET=
# Callback URL of logstream, to register in the provider (path free, /auth/callback recommended)
OIDC_REDIRECT_URL=https://logs.example.org/auth/callback
# Requested scopes (openid is always added) and session lifetime (e.g. 8h, 24h)
OIDC_SCOPES=openid profile email
OIDC_SESSION_TTL=12h
# Reverse DNS: show host names instead of IP addresses (on/off)
RDNS=on
# DNS server used for reverse lookups (e.g. your router: 192.168.1.1). Empty = system resolver