coulomb-social/docs/dev.md
tegwick 76ec8cfe41 Register coulomb-social OIDC client on live KeyCape (CSOC-WP-0002-T03)
Public PKCE client on kc.coulomb.social with local and production redirect
URIs. Add register-keycape-client.sh, document env, and harden public-client
token exchange (no secret). Authorize probe verified registered vs reject.
2026-08-09 01:50:51 +02:00

1.7 KiB

Local development

Prerequisites

  • Python 3.12+
  • uv

Setup

cd ~/coulomb-social
uv sync
uv run manage.py migrate
uv run manage.py runserver 0.0.0.0:8008

Open http://127.0.0.1:8008/Sign in uses dev claims when OIDC_ENABLED=false (default) and DEBUG=true.

Tests

make test
# or
uv run pytest

Environment

See .env.example. Summary:

Variable Default Purpose
SECRET_KEY insecure dev default Django secret
DATABASE_URL sqlite ./db.sqlite3 DB
DEFAULT_TENANT_ID binky Client #1 tenant key
OIDC_ENABLED false Use KeyCape / real issuer
OIDC_ISSUER e.g. https://kc.coulomb.social
OIDC_CLIENT_ID coulomb-social
OIDC_CLIENT_SECRET empty public client — leave empty
OIDC_REDIRECT_URI http://127.0.0.1:8008/auth/callback/
USER_ENGINE_BASE_URL empty (stub) user-engine HTTP
USER_ENGINE_APPLICATION_ID coulomb-social App id in user-engine
FLEX_AUTH_BASE_URL empty (fail-closed except shell:view) PDP

Platform OIDC (KeyCape)

Client is registered on railiance01 KeyCape. Re-apply if redirect URIs change:

./scripts/register-keycape-client.sh

Then:

export OIDC_ENABLED=true
export OIDC_ISSUER=https://kc.coulomb.social
export OIDC_CLIENT_ID=coulomb-social
export OIDC_REDIRECT_URI=http://127.0.0.1:8008/auth/callback/
export OIDC_SCOPES="openid profile email groups"
make run

Sign-in redirects to Authelia (auth.coulomb.social) + MFA via privacyIDEA.

See docs/adr/ADR-0001-netkingdom-identity.md and docs/identity/.