feat(config): add tokenUrl, clientId, clientSecret to auth config
CI / CI (pull_request) Successful in 3m20s

Wire token exchange config for /auth/token and /auth/refresh endpoints.
clientSecret loaded from AUTH_CLIENT_SECRET env var (never from YAML).
Backward compatible — missing fields default to zero values.

3 new tests covering: full config, env-only secret, backward compat.

Closes homelab#12

Co-authored-by: poimen <[email protected]>
This commit is contained in:
Admin Bot
2026-09-08 16:25:32 -07:00
co-authored by poimen
parent 09318778fa
commit 136c85ad13
6 changed files with 125 additions and 0 deletions
+6
View File
@@ -50,6 +50,12 @@ type AuthConfig struct {
JWKSURL string
// RequiredCapability is the permission required for LLM inference (e.g., "llm:inference").
RequiredCapability string
// TokenURL is the Authentik token endpoint for password/refresh grants.
TokenURL string
// ClientID is the OAuth2 client ID for token exchange.
ClientID string
// ClientSecret is the OAuth2 client secret (loaded from env, never from config file).
ClientSecret string
}
// Route represents a single route and its upstream configuration.