coulomb-social/docs/identity/oidc-client.md
tegwick f5537d8365 Serve the rebuild on app.coulomb.social; defer apex Bubble cutover
Document parallel-host strategy: Railiance on app.*, Bubble remains on
coulomb.social until data and self-registration are ready.
2026-08-09 23:20:30 +02:00

50 lines
1.9 KiB
Markdown

# OIDC client binding (coulomb.social)
Non-secret registration checklist for NetKingdom IAM Profile issuers.
| Field | Value / notes |
|-------|----------------|
| Application | coulomb.social |
| Profile | NetKingdom IAM Profile (PKCE S256 required) |
| Issuer (live) | `https://kc.coulomb.social` (KeyCape lightweight mode) |
| client_id | `coulomb-social` |
| client_type | **public** (no client secret; PKCE only) |
| redirect_uri (dev) | `http://127.0.0.1:8008/auth/callback/` · `http://localhost:8008/auth/callback/` |
| redirect_uri (public app) | `https://app.coulomb.social/auth/callback/` (**live** host while Bubble keeps apex) |
| redirect_uri (apex future) | `https://coulomb.social/auth/callback/` (registered; cutover deferred) |
| scopes | `openid profile email groups` |
| grant | authorization_code |
| wildcard redirects | **forbidden** |
## Status
| Environment | Issuer mode | Registered |
|-------------|-------------|------------|
| local offline | dev claims (`OIDC_ENABLED=false`) | n/a |
| platform (railiance01) | KeyCape @ `kc.coulomb.social` | **yes** (2026-08-09) |
| key-cape dev-config | local compose | yes (repo `config/dev-config.yaml`) |
### Live verification (2026-08-09)
- Registered via `scripts/register-keycape-client.sh`
`net-kingdom/sso-mfa/k8s/keycape/register-coulomb-social.sh` (patches
`sso/keycape-config`, rolls out KeyCape).
- `GET /authorize` with registered redirect → **200**, browser handoff to Authelia.
- Unregistered redirect → **400** `invalid_profile_usage` / `redirect_uri does not match`.
### Enable in the app
```bash
export OIDC_ENABLED=true
export OIDC_ISSUER=https://kc.coulomb.social
export OIDC_CLIENT_ID=coulomb-social
export OIDC_REDIRECT_URI=http://127.0.0.1:8008/auth/callback/
# leave OIDC_CLIENT_SECRET unset (public client)
make run
```
Re-register after redirect URI changes:
```bash
./scripts/register-keycape-client.sh
```