Hydra 为 iam-login /console 开启 CORS 并记录管理客户端登记
yaml / yaml (pull_request) Successful in 21s

iam-login 的 /console 是 Hydra public 客户端,浏览器直接向 Hydra
换取 token,因此 public 端口开启 CORS,只放行开发实例 origin,不放行
cookie 凭据;Gitea 等服务端客户端不受影响。README 记录 iam-admin-ui
经 Admin 带外登记的方法。

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-01 16:42:07 +00:00
co-authored by Claude Opus 5.5
parent cd9d461950
commit 5fd00be136
2 changed files with 39 additions and 1 deletions
+14
View File
@@ -1,6 +1,20 @@
serve:
public:
port: 4444
# The iam-login /console admin UI is a public OIDC client that exchanges its code from the
# browser, so only that origin may call the public endpoints cross-origin. Server-side
# clients such as Gitea are unaffected by CORS.
cors:
enabled: true
allowed_origins:
- https://laptop.tail7e769.ts.net:18082
allowed_methods:
- GET
- POST
allowed_headers:
- Authorization
- Content-Type
allow_credentials: false
admin:
port: 4445
tls: