updated versions and added privacy page

This commit is contained in:
bobban committed 2026-09-04 23:54:37 +02:00
1 parent fd9ae07602
commit 069553f0eb
9 files changed
+368 -20

No files matched your search

+29
View File
@@ -62,6 +62,30 @@ The cPanel account must own the domains you want to manage. Uses the cPanel UAPI
---
## Authentik SSO
Single sign-on via Authentik (optional). When configured, a **Sign in with Authentik** button appears on the login page alongside the regular username/password form. Users who sign in via SSO for the first time are automatically created as local accounts.
| Variable | Required | Description |
|----------|----------|-------------|
| `AUTHENTIK_URL` | Yes | Issuer URL of your Authentik application, e.g. `https://auth.example.com/application/o/sloth-manager` |
| `AUTHENTIK_CLIENT_ID` | Yes | Client ID from the Authentik OAuth2/OIDC Provider |
| `AUTHENTIK_CLIENT_SECRET` | Yes | Client secret from the Authentik OAuth2/OIDC Provider |
**Setup steps in Authentik:**
1. Go to **Applications → Providers → Create** and choose **OAuth2/OpenID Provider**.
2. Set **Client type** to `Confidential`.
3. Under **Redirect URIs**, add your Sloth Manager URL with a trailing slash, e.g. `https://slothmgmt.example.com/`.
The trailing slash is required — Authentik does exact-match on redirect URIs.
4. Copy the **Client ID** and **Client Secret** into your `.env`.
5. Go to **Applications → Applications → Create**, select the provider, and note the **Slug**.
6. Set `AUTHENTIK_URL` to `https://your-authentik-host/application/o/<slug>`.
SSO is disabled (and the button is hidden) when any of the three `AUTHENTIK_*` variables are missing.
---
## Authentication
| Variable | Required | Description |
@@ -110,6 +134,11 @@ CPANEL_USERNAME=myuser
CPANEL_API_TOKEN=your_token
CPANEL_INSECURE=false
# Authentik SSO (optional)
AUTHENTIK_URL=https://auth.example.com/application/o/sloth-manager
AUTHENTIK_CLIENT_ID=your_client_id
AUTHENTIK_CLIENT_SECRET=your_client_secret
# Auth
JWT_SECRET=your-long-random-secret-here
JWT_EXPIRES_IN=24h