- Serve multiple domains (RP IDs) from one instance: host-based dispatch, per-domain credentials and sessions, domains managed at runtime in the admin UI — previously one RP per instance - Cross-domain sign-in via Related Origin Requests: per-domain related-origins list with a served .well-known/webauthn document - Explicit per-domain origin lists with shell-glob wildcards (**. for apex + any subdomain depth, *. for one level), editable in the admin UI with validation and self-lockout guards - Per-domain auth hosts: the account/admin UI can live on a different host per domain, no longer confined to subdomains of a single RP - CLI: 'paskia init <rp-id [rp-name]' initializes or adds a domain to an existing database; 'paskia migrate' converts legacy databases BREAKING CHANGES (v2.0): - Database schema: config is now per-domain and credentials/sessions carry an rp_id — existing databases must be converted with 'paskia migrate' - Origins are now explicit: main implicitly allowed every subdomain of the RP; configure '**.' origins to reproduce that behavior - CLI: the flat '--rp-id/--rp-name/--origin/--auth/--save' flags are replaced by the 'init' and 'migrate' subcommandsReviewed-on: #4
23 lines
771 B
Plaintext
23 lines
771 B
Plaintext
# Permission to use within your endpoints that need authentication/authorization
|
|
# Argument is mandatory and provides a query string to /auth/api/forward
|
|
# "" means just authentication
|
|
# perm=yourservice:login to require specific permission
|
|
# public=1 to allow public access (backend must check Remote-Public)
|
|
forward_auth {$AUTH_UPSTREAM:localhost:4401} {
|
|
uri /auth/api/forward?{args[0]}
|
|
header_up Connection keep-alive # Much higher performance
|
|
header_up -Upgrade # Disable Upgrade: WebSocket
|
|
copy_headers {
|
|
Remote-Public
|
|
Remote-User
|
|
Remote-Name
|
|
Remote-Groups
|
|
Remote-Org
|
|
Remote-Org-Name
|
|
Remote-Role
|
|
Remote-Role-Name
|
|
Remote-Session-Expires
|
|
Remote-Credential
|
|
}
|
|
}
|