Enable PKCE for ArgoCD OIDC login #477
@@ -26,6 +26,10 @@ data:
|
||||
issuer: https://identity.unkin.net/application/o/argocd/
|
||||
clientID: argocd
|
||||
clientSecret: $argocd-oidc:client_secret
|
||||
# The Authentik client is public (the iOS app can't hold a secret), so
|
||||
# Authentik no longer enforces clientSecret; PKCE replaces it as the
|
||||
# protection against authorization-code interception.
|
||||
enablePKCEAuthentication: true
|
||||
# identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the
|
||||
# stock image trust store validates it; no rootCA pin.
|
||||
requestedScopes:
|
||||
|
||||
Reference in New Issue
Block a user