@senti100/dsh-oidc
Provider-neutral OpenID Connect admission for DeepSeek Harness Web 适合需要为Web端配置统一身份认证与准入控制的系统管理员。
설치
검증된 bundle이 없거나 호환성 검사에 실패했습니다. 먼저 저장소 설명을 읽어 주세요. 전체 README 읽기 ↗
Configuration
| Field | Meaning |
|---|---|
issuer | Exact HTTPS issuer identifier used for discovery and token validation. |
clientId | Exact OIDC client identifier. |
clientSecretRef | Optional DSH credential reference name. The secret value is resolved for each login/callback/logout operation and is never configuration. Omit for a public client. |
publicOrigin | Fixed HTTPS origin, path /; never derived from Host or forwarded headers. |
allowedSubjects | Exact { issuer, subject } tuples. |
allowedEmails | Exact email values as an additional policy category, never identity; admission also requires literal boolean email_verified: true. |
allowedGroups | Exact case-sensitive values from groupsClaim. |
groupMode | any or all for configured allowed groups. |
requiredClaims | Exact allowed values per required claim; categories are ANDed. |
sessionMaxAgeSeconds | Absolute local OIDC-session lifetime (default 8 hours). |
sessionIdleTimeoutSeconds | Idle expiry (default 30 minutes). Provider policy changes do not invalidate an already-issued session before these limits. |
At least one allow category is mandatory. Every configured category is ANDed; values within subject, email, and any group categories are ORed. Match comparison is byte-exact with no case folding or substring behavior. Explicit empty policy lists are invalid. Group claims must be nonempty bounded arrays of unique nonempty bounded strings; scalar groups always deny. Custom required claims may be one bounded nonempty string or the same bounded unique-string array shape.
See the step-by-step deployment and rollback guide, examples/cordis.patch.yml, examples/Caddyfile, and .env.example. Before sign-in, the bare root is expected to return 401; open https://dsh.example/auth/login (substitute your hostname) to begin OIDC. This checkout and its local tarball are the current distribution path; the package is not assumed to be on npm. Configuration values in the patch are environment-backed; the client secret value stays behind ctx.credentials and only its reference name appears in plugin config.