mirror of
https://github.com/volcengine/OpenViking.git
synced 2026-10-01 17:57:49 +08:00
#2160 dropped the legacy `/console` standalone service but deliberately left the OAuth authorize page's `/console` link and Quick-authorize panel in place, calling out a follow-up to re-point them at web-studio. This PR is that follow-up. Backend - `provider.authorize()` now defaults to redirecting to `/studio/oauth/consent` (same-origin SPA) instead of the server-rendered `/oauth/authorize/page`. New `FALLBACK_AUTHORIZE_PAGE` constant exposed for callers that need to opt into the legacy path. - New public endpoint `GET /api/v1/auth/oauth/pending/{pending_id}` returns the minimum info the consent UI needs (client_name, redirect_host, scopes); deliberately does NOT expose display_code or full redirect_uri. - `POST /api/v1/auth/oauth-verify` now accepts either `pending_id` (Studio consent path) or `code` (cross-device fallback). - HTML `/oauth/authorize/page` template stripped of `/console` link, the `/console/api/v1/...` JS, and the Quick-authorize same-origin panel. It now serves as a pure cross-device fallback that points users at `/studio/oauth/verify` on another already-signed-in device. Web Studio - New `<IdentityPicker>` shared component: "current identity" or "use a different API key" — the temporary key is never persisted. - New routes `/studio/oauth/consent` (same-device consent card) and `/studio/oauth/verify` (cross-device code entry). - ConnectionDialog gains an "OAuth client OTP" section (same IdentityPicker), driving `POST /api/v1/auth/otp`. - API key storage is unchanged: only sessionStorage. No new localStorage writes, no cross-tab channels — the consent UI runs inside Studio's own tab, so it reads the session-stored key directly. Docs - 11-oauth.md (zh/en): refreshed quickstart, How-it-works, Claude.ai walkthrough, curl example, and troubleshooting around the Studio consent / cross-device verify split. - 12-public-access.md (zh/en): rewritten to lead with public HTTPS; the `:1934` Caddy block is now a one-paragraph compatibility note for deployments that already bookmarked it. - mcp-oauth2-1.md: top-level "Studio migration" note explains the new default path; Phase 1 history retained. - Caddyfile / docker-compose.yml comments reworded from "aggregated proxy" to "legacy fallback" to match the new docs. Tests - `tests/server/oauth/test_router.py` fixture pins to FALLBACK_AUTHORIZE_PAGE so existing end-to-end assertions keep working. - 4 new tests cover the pending-info endpoint and pending_id verify path. - 55 passed locally; ruff format+check, web-studio tsc/eslint/prettier all clean. Security notes - Consent UI requires explicit user click; client_name + redirect_host shown for phishing identification. - Knowing a pending_id does not bypass Bearer auth. - display_code is not returned by GET pending — the cross-device brute-force protection is preserved. - `ctx.from_oauth` gate (router.py) untouched: OAuth bearer still cannot mint new OAuth state or OTPs.
65 lines
2.0 KiB
YAML
65 lines
2.0 KiB
YAML
version: "3.8"
|
|
|
|
# Set OPENVIKING_PUBLIC_BASE_URL in a `.env` file next to this compose file
|
|
# when you need public HTTPS (OAuth, MCP clients on the internet).
|
|
#
|
|
# .env example for local-only (leave unset or empty):
|
|
# # no .env needed — just `docker compose up -d`
|
|
#
|
|
# .env example for public HTTPS:
|
|
# OPENVIKING_PUBLIC_BASE_URL=https://ov.your-domain.com
|
|
# OV_ACME_EMAIL=admin@your-domain.com
|
|
#
|
|
# See docs/en/guides/12-public-access.md for the full walkthrough.
|
|
|
|
services:
|
|
openviking:
|
|
image: ghcr.io/volcengine/openviking:latest
|
|
container_name: openviking
|
|
# Direct access (optional — caddy:1934 is the recommended single entry
|
|
# point). Comment this out once Caddy is your only ingress.
|
|
ports:
|
|
- "1933:1933"
|
|
volumes:
|
|
- ~/.openviking:/app/.openviking
|
|
environment:
|
|
OPENVIKING_PUBLIC_BASE_URL: ${OPENVIKING_PUBLIC_BASE_URL:-}
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "curl -fsS http://127.0.0.1:1933/health || exit 1"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 30s
|
|
restart: unless-stopped
|
|
|
|
# Legacy reverse proxy — port 1934 is retained for existing deployments.
|
|
# New setups can connect directly to openviking:1933.
|
|
#
|
|
# For public HTTPS: edit the Caddyfile to add a domain block, set
|
|
# OPENVIKING_PUBLIC_BASE_URL in .env, uncomment the 80/443 port lines
|
|
# below, and add the caddy volumes at the bottom.
|
|
caddy:
|
|
image: caddy:2
|
|
container_name: openviking-caddy
|
|
restart: unless-stopped
|
|
ports:
|
|
- "1934:1934"
|
|
# Uncomment for public HTTPS (after adding a domain block to Caddyfile):
|
|
# - "80:80"
|
|
# - "443:443"
|
|
volumes:
|
|
- ./Caddyfile:/etc/caddy/Caddyfile:ro
|
|
# Uncomment for public HTTPS (Caddy stores certs here):
|
|
# - caddy_data:/data
|
|
# - caddy_config:/config
|
|
environment:
|
|
OPENVIKING_PUBLIC_BASE_URL: ${OPENVIKING_PUBLIC_BASE_URL:-}
|
|
OV_ACME_EMAIL: ${OV_ACME_EMAIL:-}
|
|
depends_on:
|
|
- openviking
|
|
|
|
# Uncomment for public HTTPS:
|
|
# volumes:
|
|
# caddy_data:
|
|
# caddy_config:
|