Phase 1: add OIDC client (redirect/callback/token/session) with proxyAuth header fallback

No manifest change yet — proxyAuth stays active, so get_identity() still works
via header. OIDC routes only activate when CLOUDRON_OIDC_* env vars are present.
Validates id_token signature (JWKS), iss/aud/nonce, exp/nbf.
This commit is contained in:
inference-bot committed 2026-09-23 09:13:37 -06:00
1 parent 30ca7cbcf3
commit 048654d000
3 files changed
+252 -1

No files matched your search

+2
View File
@@ -1,3 +1,5 @@
fastapi==0.115.0
uvicorn[standard]==0.30.6
httpx==0.27.2
authlib==1.3.0
itsdangerous==2.1.2