From 278f61844675775af9532e9812f8138ba1deabb8 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Tue, 15 Apr 2025 22:26:50 -0400 Subject: In progress attempt to use Dex for OIDC Dex really doesn't want to be the authoritative identity provider. Static users are not very configurable. The sub claim is a base64 internal representation that we can't use in backends directly. We could jury rig email, but never got that working. Basic authentication works, but Home Assistant fails to login the user. --- hostnix/elmo/home-assistant.nix | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) (limited to 'hostnix/elmo/home-assistant.nix') diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix index 7c66951..0b23db0 100644 --- a/hostnix/elmo/home-assistant.nix +++ b/hostnix/elmo/home-assistant.nix @@ -63,7 +63,14 @@ use_x_forwarded_for = true; }; recorder.db_url = "postgresql://@/hass"; - auth_header = { }; + # FIXME doesn't authenticate + # auth_header.username_header = "X-Email"; + auth_header.debug = true; + logger = { + default = "info"; + logs."custom_components.auth_header" = "debug"; + }; + #binary_sensor: # - platform: template @@ -651,6 +658,14 @@ auth_request off; ''; }; + # FIXME testing shim + locations."/test" = { + proxyPass = "http://127.0.0.1:8000"; + extraConfig = '' + proxy_set_header X-User $user; + proxy_set_header X-Email $email; + ''; + }; # Disable service worker caching that works improperly with reverse proxy. # https://github.com/home-assistant/frontend/issues/14836 # https://community.home-assistant.io/t/disabling-service-worker-reverse-proxy-auth-causes-issues/167082 -- cgit v1.3.1