6fef7c1dc71e70b9046d016021b666d5c1b1abc9
A home site forwarded every identity route to auth_base_url, so it never knew who was visiting and could only ever offer "Sign in". It now runs the OIDC flow itself and shows "My Account" and, for admins, "Admin" -- both pointing at the deployment that owns those pages. There is no user table on a home deployment, so the session cookie carries the claims we need (username, email, admin flag) rather than a row id. It is HMAC-signed, so it is tamper-evident, and holds nothing secret. The admin test mirrors upsert_oidc_user: app_admin_emails or an admin group in the claims. Also decouples oidc_issuer from auth_base_url. They are different hosts -- Authentik on one, the accounts app on another -- and deriving one from the other only worked when they happened to coincide. OIDC_ISSUER is now its own variable, required unless APP_ROLE=home. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Description
No description provided
Languages
Python
48.9%
JavaScript
25.8%
CSS
20%
HTML
5.3%