Enable PKCE for ArgoCD OIDC login
The Authentik client is now public (iOS app needs it), so Authentik no longer enforces client_secret. PKCE replaces that as the protection against authorization-code interception.
This commit is contained in:
@@ -26,6 +26,10 @@ data:
|
|||||||
issuer: https://identity.unkin.net/application/o/argocd/
|
issuer: https://identity.unkin.net/application/o/argocd/
|
||||||
clientID: argocd
|
clientID: argocd
|
||||||
clientSecret: $argocd-oidc:client_secret
|
clientSecret: $argocd-oidc:client_secret
|
||||||
|
# The Authentik client is public (the iOS app can't hold a secret), so
|
||||||
|
# Authentik no longer enforces clientSecret; PKCE replaces it as the
|
||||||
|
# protection against authorization-code interception.
|
||||||
|
enablePKCEAuthentication: true
|
||||||
# identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the
|
# identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the
|
||||||
# stock image trust store validates it; no rootCA pin.
|
# stock image trust store validates it; no rootCA pin.
|
||||||
requestedScopes:
|
requestedScopes:
|
||||||
|
|||||||
Reference in New Issue
Block a user