2.7 KiB
Pocket ID auth for admin.familyfed.ie
admin.familyfed.ie must be protected before traffic reaches the static Astro
files. Pocket ID is an OIDC provider, so the auth check belongs in the reverse
proxy or auth middleware.
Required policy:
- Host:
admin.familyfed.ie - Required Pocket ID group:
familyfed_admin - Static upstream/root:
dist/admin/index.html
Recommended Tinyauth setup
Pocket ID's proxy guide points to Tinyauth for reverse-proxy protection, and
Tinyauth supports Pocket ID groups through the oauth.groups app label.
Create a Pocket ID OIDC client:
- Name:
FamilyFed Admin - Callback URL:
https://auth.familyfed.ie/api/oauth/callback/pocketid - Scopes:
openid email profile groups
Configure Tinyauth with the Pocket ID client:
environment:
TINYAUTH_OAUTH_AUTOREDIRECT: pocketid
TINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTID: "<pocket-id-client-id>"
TINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTSECRET: "<pocket-id-client-secret>"
TINYAUTH_OAUTH_PROVIDERS_POCKETID_AUTHURL: "https://pocket-id.familyfed.ie/authorize"
TINYAUTH_OAUTH_PROVIDERS_POCKETID_TOKENURL: "https://pocket-id.familyfed.ie/api/oidc/token"
TINYAUTH_OAUTH_PROVIDERS_POCKETID_USERINFOURL: "https://pocket-id.familyfed.ie/api/oidc/userinfo"
TINYAUTH_OAUTH_PROVIDERS_POCKETID_REDIRECTURL: "https://auth.familyfed.ie/api/oauth/callback/pocketid"
TINYAUTH_OAUTH_PROVIDERS_POCKETID_SCOPES: "openid email profile groups"
TINYAUTH_OAUTH_PROVIDERS_POCKETID_NAME: "Pocket ID"
Add app access labels for the admin host:
labels:
tinyauth.apps.familyfed-admin.config.domain: "admin.familyfed.ie"
tinyauth.apps.familyfed-admin.oauth.groups: "familyfed_admin"
Users outside familyfed_admin should receive the unauthorized page from the
auth middleware and never reach the static admin HTML.
Caddy with caddy-security
If the live proxy is Caddy with caddy-security, create a Pocket ID OIDC client
with this callback URL:
https://admin.familyfed.ie/caddy-security/oauth2/generic/authorization-code-callback
Configure the authorization policy to allow only users whose OIDC groups claim
contains familyfed_admin, then serve or reverse-proxy the static admin output.
Pocket ID's own guide documents the Caddy callback shape and OIDC provider
settings; the group condition must be added in the Caddy authorization policy.
Deployment checks
The site build now verifies that dist/admin/index.html exists. That confirms
the static admin page is available for the host, but it does not prove the
external proxy has enabled Pocket ID. Verify live protection with:
curl -I https://admin.familyfed.ie/
Expected unauthenticated behavior is a redirect to the Pocket ID/Tinyauth login
or a 401/403 response from the auth middleware.