HttpUserEngineClient uses trusted-proxy claims against live user-engine. Offline stub when URL/secret unset. Align default tenant with KeyCape tenant:coulomb; map OIDC tenant/principal_type/groups into the envelope.
1.9 KiB
1.9 KiB
Local development
Prerequisites
- Python 3.12+
uv
Setup
cd ~/coulomb-social
uv sync
uv run manage.py migrate
uv run manage.py runserver 0.0.0.0:8008
Open http://127.0.0.1:8008/ — Sign in uses dev claims when
OIDC_ENABLED=false (default) and DEBUG=true.
Tests
make test
# or
uv run pytest
Environment
See .env.example. Summary:
| Variable | Default | Purpose |
|---|---|---|
SECRET_KEY |
insecure dev default | Django secret |
DATABASE_URL |
sqlite ./db.sqlite3 |
DB |
DEFAULT_TENANT_ID |
tenant:coulomb |
Platform tenant claim (KeyCape default) |
OIDC_ENABLED |
false |
Use KeyCape / real issuer |
OIDC_ISSUER |
e.g. https://kc.coulomb.social |
|
OIDC_CLIENT_ID |
coulomb-social |
|
OIDC_CLIENT_SECRET |
empty | public client — leave empty |
OIDC_REDIRECT_URI |
http://127.0.0.1:8008/auth/callback/ |
|
USER_ENGINE_BASE_URL |
empty (stub) | e.g. https://users.92-205-62-239.nip.io |
USER_ENGINE_PROXY_SECRET |
empty | trusted proxy secret (with base URL → HTTP) |
USER_ENGINE_APPLICATION_ID |
coulomb-social |
App id |
USER_ENGINE_EXPECTED_AUDIENCE |
user-engine-portal |
required aud for /me |
FLEX_AUTH_BASE_URL |
empty (fail-closed except shell:view) | PDP |
Platform OIDC (KeyCape)
Client is registered on railiance01 KeyCape. Re-apply if redirect URIs change:
./scripts/register-keycape-client.sh
Then:
export OIDC_ENABLED=true
export OIDC_ISSUER=https://kc.coulomb.social
export OIDC_CLIENT_ID=coulomb-social
export OIDC_REDIRECT_URI=http://127.0.0.1:8008/auth/callback/
export OIDC_SCOPES="openid profile email groups"
make run
Sign-in redirects to Authelia (auth.coulomb.social) + MFA via privacyIDEA.
See docs/adr/ADR-0001-netkingdom-identity.md and docs/identity/.