fix: use secrets properly for keycloak

This commit is contained in:
Mac Chaffee
2025-09-10 20:47:05 -04:00
parent e7b150cea1
commit 8f0dc48169
3 changed files with 6 additions and 6 deletions

View File

@ -44,8 +44,6 @@ LETS_ENCRYPT_ENV=production
#KEYCLOAK_ENABLED=1
#COMPOSE_FILE="$COMPOSE_FILE:compose.keycloak.yml"
#OAUTH_CLIENT_ID=writefreely
#OAUTH_HOST=
#OAUTH_CLIENT_SECRET=
#OAUTH_LOGIN_BUTTON=
#OAUTH_WRITEFREELY_VERSION=v1
#OAUTH_HOST=https://<your domain>/auth/realms/<your realm>/protocol/openid-connect
#OAUTH_DISPLAY_NAME=Keycloak
#OAUTH_CLIENT_SECRET_VERSION=v1

View File

@ -32,7 +32,9 @@ abra app run <domain> app -- writefreely -c /usr/share/writefreely/config.ini us
## Keycloak setup
For the **OAUTH_HOST** config, it uses this format: `https://keycloak.domain.here/auth/realms/<your realm>/protocol/openid-connect`.
For the **OAUTH_HOST** config, it uses this format: `https://keycloak.example.com/auth/realms/<your realm>/protocol/openid-connect`.
To set the client secret: `abra app secret insert <domain> oauth_client_secret v1`
## MariaDB

View File

@ -57,7 +57,7 @@ disable_password_auth = {{ env "DISABLE_PASSWORD_AUTH" }}
client_id = {{ env "OAUTH_CLIENT_ID" }}
client_secret = {{ secret "oauth_client_secret" }}
host = {{ env "OAUTH_HOST" }}
display_name = {{ env "OAUTH_LOGIN_BUTTON" }}
display_name = {{ env "OAUTH_DISPLAY_NAME" }}
callback_proxy =
callback_proxy_api =
token_endpoint = /token