Public PKCE client on kc.coulomb.social with local and production redirect URIs. Add register-keycape-client.sh, document env, and harden public-client token exchange (no secret). Authorize probe verified registered vs reject.
21 lines
632 B
Text
21 lines
632 B
Text
# Copy to .env for local overrides (never commit .env).
|
|
# python-decouple loads .env automatically when present.
|
|
|
|
SECRET_KEY=change-me
|
|
DEBUG=true
|
|
DATABASE_URL=sqlite:///db.sqlite3
|
|
DEFAULT_TENANT_ID=binky
|
|
|
|
# --- NetKingdom OIDC (KeyCape) ---
|
|
# Offline shell: leave OIDC_ENABLED=false and use /auth/dev-login/
|
|
OIDC_ENABLED=false
|
|
OIDC_ISSUER=https://kc.coulomb.social
|
|
OIDC_CLIENT_ID=coulomb-social
|
|
OIDC_REDIRECT_URI=http://127.0.0.1:8008/auth/callback/
|
|
# Public client — no secret:
|
|
# OIDC_CLIENT_SECRET=
|
|
OIDC_SCOPES=openid profile email groups
|
|
|
|
USER_ENGINE_APPLICATION_ID=coulomb-social
|
|
# USER_ENGINE_BASE_URL=
|
|
# FLEX_AUTH_BASE_URL=
|