Files
OpenViking/docker-compose.yml
T
t0saki da59289591 feat(oauth): move authorize UI into web-studio (#2160 follow-up) (#2170)
#2160 dropped the legacy `/console` standalone service but deliberately
left the OAuth authorize page's `/console` link and Quick-authorize panel
in place, calling out a follow-up to re-point them at web-studio. This
PR is that follow-up.

Backend
- `provider.authorize()` now defaults to redirecting to
  `/studio/oauth/consent` (same-origin SPA) instead of the server-rendered
  `/oauth/authorize/page`. New `FALLBACK_AUTHORIZE_PAGE` constant exposed
  for callers that need to opt into the legacy path.
- New public endpoint `GET /api/v1/auth/oauth/pending/{pending_id}` returns
  the minimum info the consent UI needs (client_name, redirect_host,
  scopes); deliberately does NOT expose display_code or full redirect_uri.
- `POST /api/v1/auth/oauth-verify` now accepts either `pending_id`
  (Studio consent path) or `code` (cross-device fallback).
- HTML `/oauth/authorize/page` template stripped of `/console` link, the
  `/console/api/v1/...` JS, and the Quick-authorize same-origin panel.
  It now serves as a pure cross-device fallback that points users at
  `/studio/oauth/verify` on another already-signed-in device.

Web Studio
- New `<IdentityPicker>` shared component: "current identity" or
  "use a different API key" — the temporary key is never persisted.
- New routes `/studio/oauth/consent` (same-device consent card) and
  `/studio/oauth/verify` (cross-device code entry).
- ConnectionDialog gains an "OAuth client OTP" section (same
  IdentityPicker), driving `POST /api/v1/auth/otp`.
- API key storage is unchanged: only sessionStorage. No new localStorage
  writes, no cross-tab channels — the consent UI runs inside Studio's own
  tab, so it reads the session-stored key directly.

Docs
- 11-oauth.md (zh/en): refreshed quickstart, How-it-works, Claude.ai
  walkthrough, curl example, and troubleshooting around the Studio
  consent / cross-device verify split.
- 12-public-access.md (zh/en): rewritten to lead with public HTTPS;
  the `:1934` Caddy block is now a one-paragraph compatibility note for
  deployments that already bookmarked it.
- mcp-oauth2-1.md: top-level "Studio migration" note explains the new
  default path; Phase 1 history retained.
- Caddyfile / docker-compose.yml comments reworded from "aggregated
  proxy" to "legacy fallback" to match the new docs.

Tests
- `tests/server/oauth/test_router.py` fixture pins to
  FALLBACK_AUTHORIZE_PAGE so existing end-to-end assertions keep working.
- 4 new tests cover the pending-info endpoint and pending_id verify path.
- 55 passed locally; ruff format+check, web-studio tsc/eslint/prettier
  all clean.

Security notes
- Consent UI requires explicit user click; client_name + redirect_host
  shown for phishing identification.
- Knowing a pending_id does not bypass Bearer auth.
- display_code is not returned by GET pending — the cross-device
  brute-force protection is preserved.
- `ctx.from_oauth` gate (router.py) untouched: OAuth bearer still
  cannot mint new OAuth state or OTPs.
2026-05-21 17:57:33 +08:00

65 lines
2.0 KiB
YAML

version: "3.8"
# Set OPENVIKING_PUBLIC_BASE_URL in a `.env` file next to this compose file
# when you need public HTTPS (OAuth, MCP clients on the internet).
#
# .env example for local-only (leave unset or empty):
# # no .env needed — just `docker compose up -d`
#
# .env example for public HTTPS:
# OPENVIKING_PUBLIC_BASE_URL=https://ov.your-domain.com
# OV_ACME_EMAIL=admin@your-domain.com
#
# See docs/en/guides/12-public-access.md for the full walkthrough.
services:
openviking:
image: ghcr.io/volcengine/openviking:latest
container_name: openviking
# Direct access (optional — caddy:1934 is the recommended single entry
# point). Comment this out once Caddy is your only ingress.
ports:
- "1933:1933"
volumes:
- ~/.openviking:/app/.openviking
environment:
OPENVIKING_PUBLIC_BASE_URL: ${OPENVIKING_PUBLIC_BASE_URL:-}
healthcheck:
test: ["CMD-SHELL", "curl -fsS http://127.0.0.1:1933/health || exit 1"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
restart: unless-stopped
# Legacy reverse proxy — port 1934 is retained for existing deployments.
# New setups can connect directly to openviking:1933.
#
# For public HTTPS: edit the Caddyfile to add a domain block, set
# OPENVIKING_PUBLIC_BASE_URL in .env, uncomment the 80/443 port lines
# below, and add the caddy volumes at the bottom.
caddy:
image: caddy:2
container_name: openviking-caddy
restart: unless-stopped
ports:
- "1934:1934"
# Uncomment for public HTTPS (after adding a domain block to Caddyfile):
# - "80:80"
# - "443:443"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile:ro
# Uncomment for public HTTPS (Caddy stores certs here):
# - caddy_data:/data
# - caddy_config:/config
environment:
OPENVIKING_PUBLIC_BASE_URL: ${OPENVIKING_PUBLIC_BASE_URL:-}
OV_ACME_EMAIL: ${OV_ACME_EMAIL:-}
depends_on:
- openviking
# Uncomment for public HTTPS:
# volumes:
# caddy_data:
# caddy_config: