feat(auth): Authentik OIDC sign-in + Gravatar avatars
Adds optional SSO via Authentik (or any OIDC provider) alongside the existing password flow, and pulls profile images from the provider's `picture` claim or Gravatar so the sharing UI stops looking anonymous. Password login stays available as a recovery path; JIT provisioning and admin-group mapping are env-configurable. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -55,6 +55,11 @@ aiofiles==23.2.1
|
||||
python-jose[cryptography]==3.3.0
|
||||
passlib[bcrypt]==1.7.4
|
||||
bcrypt==4.0.1
|
||||
# OIDC single sign-on (Authentik, etc.). Authlib drives the Auth Code +
|
||||
# PKCE flow; itsdangerous signs the short-lived Starlette session cookie
|
||||
# that holds the PKCE state during the IdP round-trip.
|
||||
authlib==1.3.1
|
||||
itsdangerous==2.1.2
|
||||
|
||||
# Development
|
||||
pytest==7.4.4
|
||||
|
||||
Reference in New Issue
Block a user