From cce1d876c33e80bd4c3d6406c2114fbecd021a27 Mon Sep 17 00:00:00 2001 From: Claudio Date: Sun, 17 May 2026 22:56:07 +0200 Subject: [PATCH] fix(compose): pass OIDC env vars under the names PhotoPrism actually reads MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The compose file was using PHOTOPRISM_OIDC_ISSUER_URL / _CLIENT_ID / _CLIENT_SECRET / _PROVIDER_NAME / _REDIRECT_URI, but PhotoPrism's CLI flags are --oidc-uri / --oidc-client / --oidc-secret / --oidc-provider — so the env vars it parses are PHOTOPRISM_OIDC_URI / _CLIENT / _SECRET / _PROVIDER. With the old names PhotoPrism silently ignored them, OIDC stayed dormant, and `photoprism show config` reported blank oidc-uri / oidc-client even though everything else looked configured. Confirmed on the M0 LXC: renaming the env vars makes the Authentik "Sign in" button appear on /library/login, /api/v1/oidc/login emits a proper 302 to the IdP authorize endpoint, and the callback creates the OIDC user + session in the DB. The user-facing `.env.photoprism` keys are unchanged (OIDC_PROVIDER_NAME, OIDC_ISSUER_URL, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET); the compose file just maps them to the correct PHOTOPRISM_* targets. OIDC_REDIRECT_URI is removed because PhotoPrism derives the redirect from PHOTOPRISM_SITE_URL. --- .env.photoprism.example | 10 +++++++--- docker-compose.photoprism.yml | 18 +++++++++++++----- 2 files changed, 20 insertions(+), 8 deletions(-) diff --git a/.env.photoprism.example b/.env.photoprism.example index e165254..41dd44c 100644 --- a/.env.photoprism.example +++ b/.env.photoprism.example @@ -51,14 +51,18 @@ PP_GID=1000 # ── OIDC SSO (Authentik or equivalent) ─────────────────────────────────────── # Leave blank to keep OIDC dormant. Fill in to enable the "Sign in with OIDC" -# button on the login page; per plan, OIDC_REGISTER=true auto-creates -# accounts at role `user`. +# button on the login page; OIDC_REGISTER=true auto-creates accounts at role +# `user` (override to `admin` to grant full access on first SSO login). +# +# The compose file reads these and maps them to PhotoPrism's actual env-var +# names (PHOTOPRISM_OIDC_URI / _CLIENT / _SECRET / _PROVIDER) — see the +# comment in docker-compose.photoprism.yml. The PhotoPrism callback URI is +# auto-derived from PP_SITE_URL; do not set it manually. # OIDC_PROVIDER_NAME=Authentik # OIDC_ISSUER_URL=https://auth.example.com/application/o/photoprism/ # OIDC_CLIENT_ID=... # OIDC_CLIENT_SECRET=... -# OIDC_REDIRECT_URI=http://localhost:2342/api/v1/oidc/redirect # OIDC_SCOPES=openid profile email # OIDC_REGISTER=true # OIDC_ROLE=user diff --git a/docker-compose.photoprism.yml b/docker-compose.photoprism.yml index 7d87488..663dfe3 100644 --- a/docker-compose.photoprism.yml +++ b/docker-compose.photoprism.yml @@ -107,14 +107,22 @@ services: PHOTOPRISM_DISABLE_EXIFTOOL: "false" # OIDC — set in .env.photoprism when the IdP (Authentik) is wired up. # Empty values keep OIDC dormant; the username/password login still works. - PHOTOPRISM_OIDC_PROVIDER_NAME: ${OIDC_PROVIDER_NAME:-} - PHOTOPRISM_OIDC_ISSUER_URL: ${OIDC_ISSUER_URL:-} - PHOTOPRISM_OIDC_CLIENT_ID: ${OIDC_CLIENT_ID:-} - PHOTOPRISM_OIDC_CLIENT_SECRET: ${OIDC_CLIENT_SECRET:-} - PHOTOPRISM_OIDC_REDIRECT_URI: ${OIDC_REDIRECT_URI:-} + # PhotoPrism's CLI flags are --oidc-uri / --oidc-client / --oidc-secret + # / --oidc-provider, so the env-var names it actually reads are + # PHOTOPRISM_OIDC_URI / _CLIENT / _SECRET / _PROVIDER (NOT _ISSUER_URL + # / _CLIENT_ID / _CLIENT_SECRET / _PROVIDER_NAME — those are silently + # ignored, OIDC stays dormant, and `photoprism show config` reports + # blank oidc-uri / oidc-client). PHOTOPRISM_OIDC_REDIRECT is a bool + # (auto-redirect-from-/library/login), not a URL — PhotoPrism builds + # the callback from PHOTOPRISM_SITE_URL. + PHOTOPRISM_OIDC_PROVIDER: ${OIDC_PROVIDER_NAME:-${OIDC_PROVIDER:-}} + PHOTOPRISM_OIDC_URI: ${OIDC_ISSUER_URL:-${OIDC_URI:-}} + PHOTOPRISM_OIDC_CLIENT: ${OIDC_CLIENT_ID:-${OIDC_CLIENT:-}} + PHOTOPRISM_OIDC_SECRET: ${OIDC_CLIENT_SECRET:-${OIDC_SECRET:-}} PHOTOPRISM_OIDC_SCOPES: ${OIDC_SCOPES:-openid profile email} PHOTOPRISM_OIDC_REGISTER: ${OIDC_REGISTER:-true} PHOTOPRISM_OIDC_ROLE: ${OIDC_ROLE:-user} + PHOTOPRISM_OIDC_REDIRECT: ${OIDC_REDIRECT:-false} working_dir: /photoprism volumes: # Existing photo library — mounted read-only in M0; flip to :rw in M2