diff options
Diffstat (limited to 'hostnix/elmo/home-assistant.nix')
| -rw-r--r-- | hostnix/elmo/home-assistant.nix | 23 |
1 files changed, 5 insertions, 18 deletions
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix index a3cc2f1..3c62fd4 100644 --- a/hostnix/elmo/home-assistant.nix +++ b/hostnix/elmo/home-assistant.nix @@ -22,8 +22,7 @@ ]; customComponents = with pkgs.home-assistant-custom-components; [ adaptive_lighting - # TODO replace with auth_oidc https://github.com/christiaangoossens/hass-oidc-auth - (pkgs.callPackage ./home-assistant/auth_header.nix {}) + auth_oidc tuya_local ]; @@ -64,7 +63,10 @@ use_x_forwarded_for = true; }; recorder.db_url = "postgresql://@/hass"; - auth_header = { }; + auth_oidc = { + client_id = "9332ad56-1917-4f12-a0ef-f6ff69994cf4"; + discovery_url = "https://pi.mou.fo/.well-known/openid-configuration"; + }; #binary_sensor: # - platform: template @@ -637,19 +639,6 @@ # This is frequently used in examples but without clear explanation. It # might help with WebSockets. proxy_buffering off; - # oauth2-proxy NixOS module sets some non-standard headers, but we need - # the preferred_username claim. - auth_request_set $preferred_username $upstream_http_x_auth_request_preferred_username; - proxy_set_header X-Forwarded-Preferred-Username $preferred_username; - ''; - }; - # Duplicate relevant parts of root route to skip oauth2-proxy module magic. - locations."/api/" = { - proxyPass = "http://[::1]:8123"; - proxyWebsockets = true; - extraConfig = '' - proxy_buffering off; - auth_request off; ''; }; # Disable service worker caching that works improperly with reverse proxy. @@ -659,6 +648,4 @@ return = ''410 "Service worker disabled: https://github.com/home-assistant/frontend/issues/14836"''; }; }; - - services.oauth2-proxy.nginx.virtualHosts = { "ha.mou.fo" = {}; }; } |
