75 lines
2.7 KiB
Markdown
75 lines
2.7 KiB
Markdown
# Pocket ID auth for admin.familyfed.ie
|
|
|
|
`admin.familyfed.ie` must be protected before traffic reaches the static Astro
|
|
files. Pocket ID is an OIDC provider, so the auth check belongs in the reverse
|
|
proxy or auth middleware.
|
|
|
|
Required policy:
|
|
|
|
- Host: `admin.familyfed.ie`
|
|
- Required Pocket ID group: `familyfed_admin`
|
|
- Static upstream/root: `dist/admin/index.html`
|
|
|
|
## Recommended Tinyauth setup
|
|
|
|
Pocket ID's proxy guide points to Tinyauth for reverse-proxy protection, and
|
|
Tinyauth supports Pocket ID groups through the `oauth.groups` app label.
|
|
|
|
Create a Pocket ID OIDC client:
|
|
|
|
- Name: `FamilyFed Admin`
|
|
- Callback URL: `https://auth.familyfed.ie/api/oauth/callback/pocketid`
|
|
- Scopes: `openid email profile groups`
|
|
|
|
Configure Tinyauth with the Pocket ID client:
|
|
|
|
```yaml
|
|
environment:
|
|
TINYAUTH_OAUTH_AUTOREDIRECT: pocketid
|
|
TINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTID: "<pocket-id-client-id>"
|
|
TINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTSECRET: "<pocket-id-client-secret>"
|
|
TINYAUTH_OAUTH_PROVIDERS_POCKETID_AUTHURL: "https://pocket-id.familyfed.ie/authorize"
|
|
TINYAUTH_OAUTH_PROVIDERS_POCKETID_TOKENURL: "https://pocket-id.familyfed.ie/api/oidc/token"
|
|
TINYAUTH_OAUTH_PROVIDERS_POCKETID_USERINFOURL: "https://pocket-id.familyfed.ie/api/oidc/userinfo"
|
|
TINYAUTH_OAUTH_PROVIDERS_POCKETID_REDIRECTURL: "https://auth.familyfed.ie/api/oauth/callback/pocketid"
|
|
TINYAUTH_OAUTH_PROVIDERS_POCKETID_SCOPES: "openid email profile groups"
|
|
TINYAUTH_OAUTH_PROVIDERS_POCKETID_NAME: "Pocket ID"
|
|
```
|
|
|
|
Add app access labels for the admin host:
|
|
|
|
```yaml
|
|
labels:
|
|
tinyauth.apps.familyfed-admin.config.domain: "admin.familyfed.ie"
|
|
tinyauth.apps.familyfed-admin.oauth.groups: "familyfed_admin"
|
|
```
|
|
|
|
Users outside `familyfed_admin` should receive the unauthorized page from the
|
|
auth middleware and never reach the static admin HTML.
|
|
|
|
## Caddy with caddy-security
|
|
|
|
If the live proxy is Caddy with `caddy-security`, create a Pocket ID OIDC client
|
|
with this callback URL:
|
|
|
|
```text
|
|
https://admin.familyfed.ie/caddy-security/oauth2/generic/authorization-code-callback
|
|
```
|
|
|
|
Configure the authorization policy to allow only users whose OIDC groups claim
|
|
contains `familyfed_admin`, then serve or reverse-proxy the static admin output.
|
|
Pocket ID's own guide documents the Caddy callback shape and OIDC provider
|
|
settings; the group condition must be added in the Caddy authorization policy.
|
|
|
|
## Deployment checks
|
|
|
|
The site build now verifies that `dist/admin/index.html` exists. That confirms
|
|
the static admin page is available for the host, but it does not prove the
|
|
external proxy has enabled Pocket ID. Verify live protection with:
|
|
|
|
```bash
|
|
curl -I https://admin.familyfed.ie/
|
|
```
|
|
|
|
Expected unauthenticated behavior is a redirect to the Pocket ID/Tinyauth login
|
|
or a `401`/`403` response from the auth middleware.
|