Senti100/dsh-oidc ↗★ 0

@senti100/dsh-oidc

提供跨服务商的OIDC身份验证接入。 适合需要为Web端配置统一身份认证与准入控制的系统管理员。

包名
@senti100/dsh-oidc
兼容性
待验证
Harness 依赖范围
0.1.5-rc.1
Cordis 依赖范围
4.0.2
版本
0.1.0-alpha.0
许可证
MIT
最近更新
2026年9月29日

安装

此插件尚未提供可验证的 bundle,或兼容性检查未通过。请先阅读仓库说明。 阅读完整 README ↗

Configuration

FieldMeaning
issuerExact HTTPS issuer identifier used for discovery and token validation.
clientIdExact OIDC client identifier.
clientSecretRefOptional DSH credential reference name. The secret value is resolved for each login/callback/logout operation and is never configuration. Omit for a public client.
publicOriginFixed HTTPS origin, path /; never derived from Host or forwarded headers.
allowedSubjectsExact { issuer, subject } tuples.
allowedEmailsExact email values as an additional policy category, never identity; admission also requires literal boolean email_verified: true.
allowedGroupsExact case-sensitive values from groupsClaim.
groupModeany or all for configured allowed groups.
requiredClaimsExact allowed values per required claim; categories are ANDed.
sessionMaxAgeSecondsAbsolute local OIDC-session lifetime (default 8 hours).
sessionIdleTimeoutSecondsIdle expiry (default 30 minutes). Provider policy changes do not invalidate an already-issued session before these limits.

At least one allow category is mandatory. Every configured category is ANDed; values within subject, email, and any group categories are ORed. Match comparison is byte-exact with no case folding or substring behavior. Explicit empty policy lists are invalid. Group claims must be nonempty bounded arrays of unique nonempty bounded strings; scalar groups always deny. Custom required claims may be one bounded nonempty string or the same bounded unique-string array shape.

See the step-by-step deployment and rollback guide, examples/cordis.patch.yml, examples/Caddyfile, and .env.example. Before sign-in, the bare root is expected to return 401; open https://dsh.example/auth/login (substitute your hostname) to begin OIDC. This checkout and its local tarball are the current distribution path; the package is not assumed to be on npm. Configuration values in the patch are environment-backed; the client secret value stays behind ctx.credentials and only its reference name appears in plugin config.