The compose file was using PHOTOPRISM_OIDC_ISSUER_URL / _CLIENT_ID / _CLIENT_SECRET / _PROVIDER_NAME / _REDIRECT_URI, but PhotoPrism's CLI flags are --oidc-uri / --oidc-client / --oidc-secret / --oidc-provider — so the env vars it parses are PHOTOPRISM_OIDC_URI / _CLIENT / _SECRET / _PROVIDER. With the old names PhotoPrism silently ignored them, OIDC stayed dormant, and `photoprism show config` reported blank oidc-uri / oidc-client even though everything else looked configured. Confirmed on the M0 LXC: renaming the env vars makes the Authentik "Sign in" button appear on /library/login, /api/v1/oidc/login emits a proper 302 to the IdP authorize endpoint, and the callback creates the OIDC user + session in the DB. The user-facing `.env.photoprism` keys are unchanged (OIDC_PROVIDER_NAME, OIDC_ISSUER_URL, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET); the compose file just maps them to the correct PHOTOPRISM_* targets. OIDC_REDIRECT_URI is removed because PhotoPrism derives the redirect from PHOTOPRISM_SITE_URL.
3.2 KiB
3.2 KiB