Files
OpenViking/Caddyfile
T
t0saki da59289591 feat(oauth): move authorize UI into web-studio (#2160 follow-up) (#2170)
#2160 dropped the legacy `/console` standalone service but deliberately
left the OAuth authorize page's `/console` link and Quick-authorize panel
in place, calling out a follow-up to re-point them at web-studio. This
PR is that follow-up.

Backend
- `provider.authorize()` now defaults to redirecting to
  `/studio/oauth/consent` (same-origin SPA) instead of the server-rendered
  `/oauth/authorize/page`. New `FALLBACK_AUTHORIZE_PAGE` constant exposed
  for callers that need to opt into the legacy path.
- New public endpoint `GET /api/v1/auth/oauth/pending/{pending_id}` returns
  the minimum info the consent UI needs (client_name, redirect_host,
  scopes); deliberately does NOT expose display_code or full redirect_uri.
- `POST /api/v1/auth/oauth-verify` now accepts either `pending_id`
  (Studio consent path) or `code` (cross-device fallback).
- HTML `/oauth/authorize/page` template stripped of `/console` link, the
  `/console/api/v1/...` JS, and the Quick-authorize same-origin panel.
  It now serves as a pure cross-device fallback that points users at
  `/studio/oauth/verify` on another already-signed-in device.

Web Studio
- New `<IdentityPicker>` shared component: "current identity" or
  "use a different API key" — the temporary key is never persisted.
- New routes `/studio/oauth/consent` (same-device consent card) and
  `/studio/oauth/verify` (cross-device code entry).
- ConnectionDialog gains an "OAuth client OTP" section (same
  IdentityPicker), driving `POST /api/v1/auth/otp`.
- API key storage is unchanged: only sessionStorage. No new localStorage
  writes, no cross-tab channels — the consent UI runs inside Studio's own
  tab, so it reads the session-stored key directly.

Docs
- 11-oauth.md (zh/en): refreshed quickstart, How-it-works, Claude.ai
  walkthrough, curl example, and troubleshooting around the Studio
  consent / cross-device verify split.
- 12-public-access.md (zh/en): rewritten to lead with public HTTPS;
  the `:1934` Caddy block is now a one-paragraph compatibility note for
  deployments that already bookmarked it.
- mcp-oauth2-1.md: top-level "Studio migration" note explains the new
  default path; Phase 1 history retained.
- Caddyfile / docker-compose.yml comments reworded from "aggregated
  proxy" to "legacy fallback" to match the new docs.

Tests
- `tests/server/oauth/test_router.py` fixture pins to
  FALLBACK_AUTHORIZE_PAGE so existing end-to-end assertions keep working.
- 4 new tests cover the pending-info endpoint and pending_id verify path.
- 55 passed locally; ruff format+check, web-studio tsc/eslint/prettier
  all clean.

Security notes
- Consent UI requires explicit user click; client_name + redirect_host
  shown for phishing identification.
- Knowing a pending_id does not bypass Bearer auth.
- display_code is not returned by GET pending — the cross-device
  brute-force protection is preserved.
- `ctx.from_oauth` gate (router.py) untouched: OAuth bearer still
  cannot mint new OAuth state or OTPs.
2026-05-21 17:57:33 +08:00

25 lines
839 B
Caddyfile

# OpenViking reverse proxy — legacy fallback
#
# Port 1934 is retained only as a legacy entrypoint for existing deployments
# that already reference it. Its primary remaining purpose is as the upstream
# target for a TLS-terminating proxy (e.g. HTTPS via Caddy domain block).
#
# For new deployments, connect directly to the OV server on port 1933.
# Web Studio is served by OV itself at /studio — no separate proxy needed.
#
# To add public HTTPS, append a domain block below (Caddy auto-provisions
# Let's Encrypt certs):
#
# {$OPENVIKING_PUBLIC_BASE_URL} {
# reverse_proxy openviking:1933
# # Optional: pin ACME email
# # tls {$OV_ACME_EMAIL}
# }
#
# Then expose ports 80/443 in docker-compose.yml and set
# OPENVIKING_PUBLIC_BASE_URL=https://your-domain.com in .env.
:1934 {
reverse_proxy openviking:1933
}