summaryrefslogtreecommitdiff
path: root/hostnix/elmo/home-assistant.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/elmo/home-assistant.nix')
-rw-r--r--hostnix/elmo/home-assistant.nix23
1 files changed, 5 insertions, 18 deletions
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix
index a3cc2f1..3c62fd4 100644
--- a/hostnix/elmo/home-assistant.nix
+++ b/hostnix/elmo/home-assistant.nix
@@ -22,8 +22,7 @@
];
customComponents = with pkgs.home-assistant-custom-components; [
adaptive_lighting
- # TODO replace with auth_oidc https://github.com/christiaangoossens/hass-oidc-auth
- (pkgs.callPackage ./home-assistant/auth_header.nix {})
+ auth_oidc
tuya_local
];
@@ -64,7 +63,10 @@
use_x_forwarded_for = true;
};
recorder.db_url = "postgresql://@/hass";
- auth_header = { };
+ auth_oidc = {
+ client_id = "9332ad56-1917-4f12-a0ef-f6ff69994cf4";
+ discovery_url = "https://pi.mou.fo/.well-known/openid-configuration";
+ };
#binary_sensor:
# - platform: template
@@ -637,19 +639,6 @@
# This is frequently used in examples but without clear explanation. It
# might help with WebSockets.
proxy_buffering off;
- # oauth2-proxy NixOS module sets some non-standard headers, but we need
- # the preferred_username claim.
- auth_request_set $preferred_username $upstream_http_x_auth_request_preferred_username;
- proxy_set_header X-Forwarded-Preferred-Username $preferred_username;
- '';
- };
- # Duplicate relevant parts of root route to skip oauth2-proxy module magic.
- locations."/api/" = {
- proxyPass = "http://[::1]:8123";
- proxyWebsockets = true;
- extraConfig = ''
- proxy_buffering off;
- auth_request off;
'';
};
# Disable service worker caching that works improperly with reverse proxy.
@@ -659,6 +648,4 @@
return = ''410 "Service worker disabled: https://github.com/home-assistant/frontend/issues/14836"'';
};
};
-
- services.oauth2-proxy.nginx.virtualHosts = { "ha.mou.fo" = {}; };
}