- devserver bootstraps via one-shot 'paskia init' when no database exists (multi --rp-id, --rp-name/--auth-host/--origin apply to the default realm), then runs plain 'paskia' serve which reads all realm configuration from the database; legacy *.paskiadb is adopted by serve without init. - Caddy origins iterate all bootstrap rp-ids. - vite.config.js accepts a comma-separated PASKIA_AUTH_HOST list and proxies /.well-known/webauthn to the backend so ROR works in dev. - caddy/auth/setup forwards /.well-known/openid-configuration and /.well-known/webauthn to paskia (they must not be swallowed by a static /.well-known/* file handler); Caddyfile.dev updated to match the generated dev config.
14 lines
414 B
Caddyfile
14 lines
414 B
Caddyfile
localhost {
|
|
# WebSockets bypass directly to backend (workaround for bun proxy bug)
|
|
# Avoids bug https://github.com/oven-sh/bun/issues/9882
|
|
handle /auth/ws/* {
|
|
reverse_proxy :4402 # directly to backend
|
|
}
|
|
# Everything else goes to or via Vite
|
|
# (Vite proxies /auth/api, /.well-known/openid-configuration and
|
|
# /.well-known/webauthn to the backend)
|
|
handle {
|
|
reverse_proxy :4403 # vite dev server
|
|
}
|
|
}
|