diff options
| author | Joe Mou <dev@mou.fo> | 2025-12-31 00:10:33 -0800 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2025-12-31 01:05:59 -0800 |
| commit | e125179918501d806e87dc170ab85d89db1f7795 (patch) | |
| tree | 391917d385b65c3c96b13a65d342a68d74dc17ff /hostnix | |
| parent | 013d42ffafb9dcd05b1bd8511a720d173fbd5c2f (diff) | |
Configure OIDC for Home Assistant
Replaces unmaintained header authentication behind oauth2-proxy.
Add OIDC client for Home Assistant:
- Callback URLs: https://ha.mou.fo/auth/oidc/callback
- Public Client
To link OIDC credentials with the existing joe user, temporarily set:
auth_oidc.features.automatic_user_linking = true;
See https://github.com/christiaangoossens/hass-oidc-auth/blob/main/docs/configuration.md#migrating-from-ha-usernamepassword-users-to-oidc-users
Must login through either:
- https://ha.mou.fo/auth/oidc/welcome
- https://ha.mou.fo/auth/oidc/redirect
Injecting directly into the landing login page is pending
https://github.com/christiaangoossens/hass-oidc-auth/issues/19
Diffstat (limited to 'hostnix')
| -rw-r--r-- | hostnix/elmo/home-assistant.nix | 23 | ||||
| -rw-r--r-- | hostnix/elmo/home-assistant/auth_header.nix | 29 |
2 files changed, 5 insertions, 47 deletions
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix index a3cc2f1..3c62fd4 100644 --- a/hostnix/elmo/home-assistant.nix +++ b/hostnix/elmo/home-assistant.nix @@ -22,8 +22,7 @@ ]; customComponents = with pkgs.home-assistant-custom-components; [ adaptive_lighting - # TODO replace with auth_oidc https://github.com/christiaangoossens/hass-oidc-auth - (pkgs.callPackage ./home-assistant/auth_header.nix {}) + auth_oidc tuya_local ]; @@ -64,7 +63,10 @@ use_x_forwarded_for = true; }; recorder.db_url = "postgresql://@/hass"; - auth_header = { }; + auth_oidc = { + client_id = "9332ad56-1917-4f12-a0ef-f6ff69994cf4"; + discovery_url = "https://pi.mou.fo/.well-known/openid-configuration"; + }; #binary_sensor: # - platform: template @@ -637,19 +639,6 @@ # This is frequently used in examples but without clear explanation. It # might help with WebSockets. proxy_buffering off; - # oauth2-proxy NixOS module sets some non-standard headers, but we need - # the preferred_username claim. - auth_request_set $preferred_username $upstream_http_x_auth_request_preferred_username; - proxy_set_header X-Forwarded-Preferred-Username $preferred_username; - ''; - }; - # Duplicate relevant parts of root route to skip oauth2-proxy module magic. - locations."/api/" = { - proxyPass = "http://[::1]:8123"; - proxyWebsockets = true; - extraConfig = '' - proxy_buffering off; - auth_request off; ''; }; # Disable service worker caching that works improperly with reverse proxy. @@ -659,6 +648,4 @@ return = ''410 "Service worker disabled: https://github.com/home-assistant/frontend/issues/14836"''; }; }; - - services.oauth2-proxy.nginx.virtualHosts = { "ha.mou.fo" = {}; }; } diff --git a/hostnix/elmo/home-assistant/auth_header.nix b/hostnix/elmo/home-assistant/auth_header.nix deleted file mode 100644 index 480598e..0000000 --- a/hostnix/elmo/home-assistant/auth_header.nix +++ /dev/null @@ -1,29 +0,0 @@ -{ - lib, - buildHomeAssistantComponent, - fetchFromGitHub, -}: - -buildHomeAssistantComponent rec { - owner = "BeryJu"; - domain = "auth_header"; - version = "1.12"; - - src = fetchFromGitHub { - inherit owner; - repo = "hass-auth-header"; - tag = "v${version}"; - hash = "sha256-BPG/G6IM95g9ip2OsPmcAebi2ZvKHUpFzV4oquOFLPM="; - }; - - # isort: command not found - dontBuild = true; - - meta = with lib; { - changelog = "https://github.com/BeryJu/hass-auth-header/releases/tag/v${version}"; - description = "Home Assistant custom component which allows you to delegate authentication to a reverse proxy"; - homepage = "https://github.com/BeryJu/hass-auth-header"; - maintainers = with maintainers; [ mjm ]; - license = licenses.gpl3; - }; -} |
