From e125179918501d806e87dc170ab85d89db1f7795 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Wed, 31 Dec 2025 00:10:33 -0800 Subject: Configure OIDC for Home Assistant Replaces unmaintained header authentication behind oauth2-proxy. Add OIDC client for Home Assistant: - Callback URLs: https://ha.mou.fo/auth/oidc/callback - Public Client To link OIDC credentials with the existing joe user, temporarily set: auth_oidc.features.automatic_user_linking = true; See https://github.com/christiaangoossens/hass-oidc-auth/blob/main/docs/configuration.md#migrating-from-ha-usernamepassword-users-to-oidc-users Must login through either: - https://ha.mou.fo/auth/oidc/welcome - https://ha.mou.fo/auth/oidc/redirect Injecting directly into the landing login page is pending https://github.com/christiaangoossens/hass-oidc-auth/issues/19 --- hostnix/elmo/home-assistant.nix | 23 +++++------------------ hostnix/elmo/home-assistant/auth_header.nix | 29 ----------------------------- 2 files changed, 5 insertions(+), 47 deletions(-) delete mode 100644 hostnix/elmo/home-assistant/auth_header.nix (limited to 'hostnix/elmo') diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix index a3cc2f1..3c62fd4 100644 --- a/hostnix/elmo/home-assistant.nix +++ b/hostnix/elmo/home-assistant.nix @@ -22,8 +22,7 @@ ]; customComponents = with pkgs.home-assistant-custom-components; [ adaptive_lighting - # TODO replace with auth_oidc https://github.com/christiaangoossens/hass-oidc-auth - (pkgs.callPackage ./home-assistant/auth_header.nix {}) + auth_oidc tuya_local ]; @@ -64,7 +63,10 @@ use_x_forwarded_for = true; }; recorder.db_url = "postgresql://@/hass"; - auth_header = { }; + auth_oidc = { + client_id = "9332ad56-1917-4f12-a0ef-f6ff69994cf4"; + discovery_url = "https://pi.mou.fo/.well-known/openid-configuration"; + }; #binary_sensor: # - platform: template @@ -637,19 +639,6 @@ # This is frequently used in examples but without clear explanation. It # might help with WebSockets. proxy_buffering off; - # oauth2-proxy NixOS module sets some non-standard headers, but we need - # the preferred_username claim. - auth_request_set $preferred_username $upstream_http_x_auth_request_preferred_username; - proxy_set_header X-Forwarded-Preferred-Username $preferred_username; - ''; - }; - # Duplicate relevant parts of root route to skip oauth2-proxy module magic. - locations."/api/" = { - proxyPass = "http://[::1]:8123"; - proxyWebsockets = true; - extraConfig = '' - proxy_buffering off; - auth_request off; ''; }; # Disable service worker caching that works improperly with reverse proxy. @@ -659,6 +648,4 @@ return = ''410 "Service worker disabled: https://github.com/home-assistant/frontend/issues/14836"''; }; }; - - services.oauth2-proxy.nginx.virtualHosts = { "ha.mou.fo" = {}; }; } diff --git a/hostnix/elmo/home-assistant/auth_header.nix b/hostnix/elmo/home-assistant/auth_header.nix deleted file mode 100644 index 480598e..0000000 --- a/hostnix/elmo/home-assistant/auth_header.nix +++ /dev/null @@ -1,29 +0,0 @@ -{ - lib, - buildHomeAssistantComponent, - fetchFromGitHub, -}: - -buildHomeAssistantComponent rec { - owner = "BeryJu"; - domain = "auth_header"; - version = "1.12"; - - src = fetchFromGitHub { - inherit owner; - repo = "hass-auth-header"; - tag = "v${version}"; - hash = "sha256-BPG/G6IM95g9ip2OsPmcAebi2ZvKHUpFzV4oquOFLPM="; - }; - - # isort: command not found - dontBuild = true; - - meta = with lib; { - changelog = "https://github.com/BeryJu/hass-auth-header/releases/tag/v${version}"; - description = "Home Assistant custom component which allows you to delegate authentication to a reverse proxy"; - homepage = "https://github.com/BeryJu/hass-auth-header"; - maintainers = with maintainers; [ mjm ]; - license = licenses.gpl3; - }; -} -- cgit v1.3.1