Merge pull request #365 from outis1one/claude/gitea-standalone-setup-oxoi2e

authelia: stop hardcoding "auth." as the portal subdomain for OIDC di…
This commit is contained in:
Outis
2026-08-20 16:18:50 -04:00
committed by GitHub
4 changed files with 24 additions and 3 deletions
+1 -1
View File
@@ -258,7 +258,7 @@ _actualbudget_offer_authelia_oidc() {
return 0
fi
local _discovery_url="https://auth.${OIDC_AUTHELIA_DOMAIN}/.well-known/openid-configuration"
local _discovery_url="${OIDC_AUTHELIA_PORTAL_URL}/.well-known/openid-configuration"
cat >> "$DIR/.env" << ENV
# Written by services/actualbudget.sh's Authelia SSO step. The first OIDC
+21
View File
@@ -1694,6 +1694,19 @@ _authelia_remove_oidc_client() {
# caller must capture and use/display it now.
# OIDC_AUTHELIA_DOMAIN this Authelia instance's apex domain, for
# building discovery/authorization/token URLs.
# OIDC_AUTHELIA_PORTAL_URL the actual login-portal base URL (e.g.
# https://auth.example.com) — read back from this
# instance's own config rather than assumed,
# since the portal subdomain isn't always "auth."
# (install_authelia()/add_authelia_domain() both
# default to it, but it's plain text in
# configuration.yml and gets hand-edited on some
# boxes — e.g. a dedicated VPS instance renamed
# to "authelia." to avoid colliding with another
# instance's "auth." on a different machine).
# Use this, not a hardcoded "https://auth.$domain",
# when building a discovery/redirect URL for a
# native-OIDC app.
# Returns 1 on failure (Authelia not installed, domain undeterminable,
# secret generation failed) with the reason already logged. A client_id
# that's already registered is NOT a failure — it gets replaced (see the
@@ -1704,6 +1717,7 @@ _authelia_provision_oidc_client() {
OIDC_CLIENT_SECRET_PLAIN=""
OIDC_AUTHELIA_DOMAIN=""
OIDC_AUTHELIA_PORTAL_URL=""
local AUTHELIA_DIR="$DOCKER_DIR/authelia"
local CONFIG_FILE="$AUTHELIA_DIR/config/configuration.yml"
@@ -1728,6 +1742,13 @@ _authelia_provision_oidc_client() {
return 1
fi
# Read the real portal URL back from config instead of assuming the
# "auth." prefix — see the OIDC_AUTHELIA_PORTAL_URL out-param comment
# above for why this can't be hardcoded. Falls back to the "auth."
# default only if parsing somehow comes up empty.
OIDC_AUTHELIA_PORTAL_URL="$(awk '/^ cookies:$/{f=1; next} f && /authelia_url:/{print $2; exit}' "$CONFIG_FILE")"
[ -z "$OIDC_AUTHELIA_PORTAL_URL" ] && OIDC_AUTHELIA_PORTAL_URL="https://auth.${OIDC_AUTHELIA_DOMAIN}"
# A stale registration (e.g. from the interactive "Register an app" menu
# run previously without ever finishing — its plaintext secret was shown
# once and is gone, so the registration is dead weight either way) would
+1 -1
View File
@@ -220,7 +220,7 @@ _gitea_offer_authelia_sso() {
return 0
fi
local _discovery_url="https://auth.${OIDC_AUTHELIA_DOMAIN}/.well-known/openid-configuration"
local _discovery_url="${OIDC_AUTHELIA_PORTAL_URL}/.well-known/openid-configuration"
log_info "Adding Authelia as an authentication source in Gitea..."
if docker exec -u git gitea gitea admin auth add-oauth \
--name authelia --provider openidConnect \
+1 -1
View File
@@ -253,7 +253,7 @@ _mealie_offer_authelia_oidc() {
return 0
fi
local _discovery_url="https://auth.${OIDC_AUTHELIA_DOMAIN}/.well-known/openid-configuration"
local _discovery_url="${OIDC_AUTHELIA_PORTAL_URL}/.well-known/openid-configuration"
cat >> "$DIR/.env" << ENV
# Written by services/mealie.sh's Authelia SSO step — adds "Sign in with