yaml / yaml (pull_request) Successful in 21s
iam-login 的 /console 是 Hydra public 客户端,浏览器直接向 Hydra 换取 token,因此 public 端口开启 CORS,只放行开发实例 origin,不放行 cookie 凭据;Gitea 等服务端客户端不受影响。README 记录 iam-admin-ui 经 Admin 带外登记的方法。 Co-Authored-By: Claude Opus 5.5 <[email protected]>
42 lines
1.1 KiB
YAML
42 lines
1.1 KiB
YAML
serve:
|
|
public:
|
|
port: 4444
|
|
# The iam-login /console admin UI is a public OIDC client that exchanges its code from the
|
|
# browser, so only that origin may call the public endpoints cross-origin. Server-side
|
|
# clients such as Gitea are unaffected by CORS.
|
|
cors:
|
|
enabled: true
|
|
allowed_origins:
|
|
- https://laptop.tail7e769.ts.net:18082
|
|
allowed_methods:
|
|
- GET
|
|
- POST
|
|
allowed_headers:
|
|
- Authorization
|
|
- Content-Type
|
|
allow_credentials: false
|
|
admin:
|
|
port: 4445
|
|
tls:
|
|
allow_termination_from:
|
|
- 10.42.0.0/16
|
|
cookies:
|
|
same_site_mode: Lax
|
|
urls:
|
|
self:
|
|
issuer: https://hydra.ad.ddupan.top
|
|
public: https://hydra.ad.ddupan.top
|
|
login: https://laptop.tail7e769.ts.net:18082/oauth2/start
|
|
consent: https://laptop.tail7e769.ts.net:18082/oauth2/consent
|
|
logout: https://laptop.tail7e769.ts.net:18082/oauth2/logout
|
|
post_logout_redirect: https://laptop.tail7e769.ts.net:18082/signin
|
|
ttl:
|
|
access_token: 15m
|
|
id_token: 15m
|
|
auth_code: 5m
|
|
log:
|
|
level: info
|
|
leak_sensitive_values: false
|
|
oauth2:
|
|
expose_internal_errors: false
|