diff options
| author | Joe Mou <dev@mou.fo> | 2025-12-31 00:10:33 -0800 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2025-12-31 01:05:59 -0800 |
| commit | e125179918501d806e87dc170ab85d89db1f7795 (patch) | |
| tree | 391917d385b65c3c96b13a65d342a68d74dc17ff /hostnix/elmo/home-assistant/auth_header.nix | |
| parent | 013d42ffafb9dcd05b1bd8511a720d173fbd5c2f (diff) | |
Configure OIDC for Home Assistant
Replaces unmaintained header authentication behind oauth2-proxy.
Add OIDC client for Home Assistant:
- Callback URLs: https://ha.mou.fo/auth/oidc/callback
- Public Client
To link OIDC credentials with the existing joe user, temporarily set:
auth_oidc.features.automatic_user_linking = true;
See https://github.com/christiaangoossens/hass-oidc-auth/blob/main/docs/configuration.md#migrating-from-ha-usernamepassword-users-to-oidc-users
Must login through either:
- https://ha.mou.fo/auth/oidc/welcome
- https://ha.mou.fo/auth/oidc/redirect
Injecting directly into the landing login page is pending
https://github.com/christiaangoossens/hass-oidc-auth/issues/19
Diffstat (limited to 'hostnix/elmo/home-assistant/auth_header.nix')
| -rw-r--r-- | hostnix/elmo/home-assistant/auth_header.nix | 29 |
1 files changed, 0 insertions, 29 deletions
diff --git a/hostnix/elmo/home-assistant/auth_header.nix b/hostnix/elmo/home-assistant/auth_header.nix deleted file mode 100644 index 480598e..0000000 --- a/hostnix/elmo/home-assistant/auth_header.nix +++ /dev/null @@ -1,29 +0,0 @@ -{ - lib, - buildHomeAssistantComponent, - fetchFromGitHub, -}: - -buildHomeAssistantComponent rec { - owner = "BeryJu"; - domain = "auth_header"; - version = "1.12"; - - src = fetchFromGitHub { - inherit owner; - repo = "hass-auth-header"; - tag = "v${version}"; - hash = "sha256-BPG/G6IM95g9ip2OsPmcAebi2ZvKHUpFzV4oquOFLPM="; - }; - - # isort: command not found - dontBuild = true; - - meta = with lib; { - changelog = "https://github.com/BeryJu/hass-auth-header/releases/tag/v${version}"; - description = "Home Assistant custom component which allows you to delegate authentication to a reverse proxy"; - homepage = "https://github.com/BeryJu/hass-auth-header"; - maintainers = with maintainers; [ mjm ]; - license = licenses.gpl3; - }; -} |
