familyfedie-website/docs/POCKET-ID-AUTH.md
Loyyd 06093af633
All checks were successful
/ deploy (push) Successful in 42s
Add admin dashboard and Pocket ID auth notes
2026-06-13 09:34:28 +02:00

2.7 KiB

Pocket ID auth for admin.familyfed.ie

admin.familyfed.ie must be protected before traffic reaches the static Astro files. Pocket ID is an OIDC provider, so the auth check belongs in the reverse proxy or auth middleware.

Required policy:

  • Host: admin.familyfed.ie
  • Required Pocket ID group: familyfed_admin
  • Static upstream/root: dist/admin/index.html

Pocket ID's proxy guide points to Tinyauth for reverse-proxy protection, and Tinyauth supports Pocket ID groups through the oauth.groups app label.

Create a Pocket ID OIDC client:

  • Name: FamilyFed Admin
  • Callback URL: https://auth.familyfed.ie/api/oauth/callback/pocketid
  • Scopes: openid email profile groups

Configure Tinyauth with the Pocket ID client:

environment:
  TINYAUTH_OAUTH_AUTOREDIRECT: pocketid
  TINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTID: "<pocket-id-client-id>"
  TINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTSECRET: "<pocket-id-client-secret>"
  TINYAUTH_OAUTH_PROVIDERS_POCKETID_AUTHURL: "https://pocket-id.familyfed.ie/authorize"
  TINYAUTH_OAUTH_PROVIDERS_POCKETID_TOKENURL: "https://pocket-id.familyfed.ie/api/oidc/token"
  TINYAUTH_OAUTH_PROVIDERS_POCKETID_USERINFOURL: "https://pocket-id.familyfed.ie/api/oidc/userinfo"
  TINYAUTH_OAUTH_PROVIDERS_POCKETID_REDIRECTURL: "https://auth.familyfed.ie/api/oauth/callback/pocketid"
  TINYAUTH_OAUTH_PROVIDERS_POCKETID_SCOPES: "openid email profile groups"
  TINYAUTH_OAUTH_PROVIDERS_POCKETID_NAME: "Pocket ID"

Add app access labels for the admin host:

labels:
  tinyauth.apps.familyfed-admin.config.domain: "admin.familyfed.ie"
  tinyauth.apps.familyfed-admin.oauth.groups: "familyfed_admin"

Users outside familyfed_admin should receive the unauthorized page from the auth middleware and never reach the static admin HTML.

Caddy with caddy-security

If the live proxy is Caddy with caddy-security, create a Pocket ID OIDC client with this callback URL:

https://admin.familyfed.ie/caddy-security/oauth2/generic/authorization-code-callback

Configure the authorization policy to allow only users whose OIDC groups claim contains familyfed_admin, then serve or reverse-proxy the static admin output. Pocket ID's own guide documents the Caddy callback shape and OIDC provider settings; the group condition must be added in the Caddy authorization policy.

Deployment checks

The site build now verifies that dist/admin/index.html exists. That confirms the static admin page is available for the host, but it does not prove the external proxy has enabled Pocket ID. Verify live protection with:

curl -I https://admin.familyfed.ie/

Expected unauthenticated behavior is a redirect to the Pocket ID/Tinyauth login or a 401/403 response from the auth middleware.