# Pocket ID auth for admin.familyfed.ie `admin.familyfed.ie` must be protected before traffic reaches the static Astro files. Pocket ID is an OIDC provider, so the auth check belongs in the reverse proxy or auth middleware. Required policy: - Host: `admin.familyfed.ie` - Required Pocket ID group: `familyfed_admin` - Static upstream/root: `dist/admin/index.html` ## Recommended Tinyauth setup Pocket ID's proxy guide points to Tinyauth for reverse-proxy protection, and Tinyauth supports Pocket ID groups through the `oauth.groups` app label. Create a Pocket ID OIDC client: - Name: `FamilyFed Admin` - Callback URL: `https://auth.familyfed.ie/api/oauth/callback/pocketid` - Scopes: `openid email profile groups` Configure Tinyauth with the Pocket ID client: ```yaml environment: TINYAUTH_OAUTH_AUTOREDIRECT: pocketid TINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTID: "" TINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTSECRET: "" TINYAUTH_OAUTH_PROVIDERS_POCKETID_AUTHURL: "https://pocket-id.familyfed.ie/authorize" TINYAUTH_OAUTH_PROVIDERS_POCKETID_TOKENURL: "https://pocket-id.familyfed.ie/api/oidc/token" TINYAUTH_OAUTH_PROVIDERS_POCKETID_USERINFOURL: "https://pocket-id.familyfed.ie/api/oidc/userinfo" TINYAUTH_OAUTH_PROVIDERS_POCKETID_REDIRECTURL: "https://auth.familyfed.ie/api/oauth/callback/pocketid" TINYAUTH_OAUTH_PROVIDERS_POCKETID_SCOPES: "openid email profile groups" TINYAUTH_OAUTH_PROVIDERS_POCKETID_NAME: "Pocket ID" ``` Add app access labels for the admin host: ```yaml labels: tinyauth.apps.familyfed-admin.config.domain: "admin.familyfed.ie" tinyauth.apps.familyfed-admin.oauth.groups: "familyfed_admin" ``` Users outside `familyfed_admin` should receive the unauthorized page from the auth middleware and never reach the static admin HTML. ## Caddy with caddy-security If the live proxy is Caddy with `caddy-security`, create a Pocket ID OIDC client with this callback URL: ```text https://admin.familyfed.ie/caddy-security/oauth2/generic/authorization-code-callback ``` Configure the authorization policy to allow only users whose OIDC groups claim contains `familyfed_admin`, then serve or reverse-proxy the static admin output. Pocket ID's own guide documents the Caddy callback shape and OIDC provider settings; the group condition must be added in the Caddy authorization policy. ## Deployment checks The site build now verifies that `dist/admin/index.html` exists. That confirms the static admin page is available for the host, but it does not prove the external proxy has enabled Pocket ID. Verify live protection with: ```bash curl -I https://admin.familyfed.ie/ ``` Expected unauthenticated behavior is a redirect to the Pocket ID/Tinyauth login or a `401`/`403` response from the auth middleware.