summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2026-07-02 00:20:01 -0400
committerJoe Mou <dev@mou.fo>2026-08-11 07:17:05 -0400
commit56fb1fc9807ad5aeba428a19762796688c80c8b5 (patch)
treeeab595b1888c591892a63f8a44ab97e2f9b051cd /hostnix/elmo/oidc.nix
parent3d06200aff7594e597a9c450bec52bf7cf6ede56 (diff)
Upgrade to NixOS 26.05
Diffstat (limited to 'hostnix/elmo/oidc.nix')
-rw-r--r--hostnix/elmo/oidc.nix3
1 files changed, 3 insertions, 0 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index 40a0528..ebdd19a 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -11,6 +11,7 @@
# - PKCE
services.pocket-id = {
enable = true;
+ credentials.ENCRYPTION_KEY = "/var/secrets/pocket-id.key";
settings = {
APP_URL = "https://pi.mou.fo";
TRUST_PROXY = true;
@@ -46,6 +47,7 @@
nginx.domain = "op.mou.fo";
setXauthrequest = true; # let oauth2-proxy nginx module pass X-User/X-Email
reverseProxy = true;
+ trustedProxyIP = [ "127.0.0.1" ];
provider = "oidc";
clientID = "39edd929-8983-4cb6-b1cd-dc08e2e3358f";
oidcIssuerUrl = "https://pi.mou.fo";
@@ -56,6 +58,7 @@
extraConfig = {
code-challenge-method = "S256";
whitelist-domain = ".mou.fo"; # allowed redirects after authentication
+ insecure-oidc-allow-unverified-email = true;
};
};