Phase 1: add OIDC client with proxyAuth header fallback

Replicates the admin-panel OIDC pattern: redirect/callback/token exchange
(client_secret_post) / JWKS validate / signed session cookie. get_user_identity()
prefers the OIDC session and falls back to the proxyAuth header. Adds /logout
route (was previously only a link). No manifest change yet.
This commit is contained in:
inference-bot committed 2026-09-23 14:06:08 -06:00
1 parent c4990ab8f0
commit 91ac38e534
3 files changed
+240 -6

No files matched your search

+2
View File
@@ -2,3 +2,5 @@ fastapi==0.115.0
uvicorn[standard]==0.30.6
httpx==0.27.2
jinja2==3.1.4
authlib==1.3.0
itsdangerous==2.1.2