diff --git a/backend/src/routes/oidc.js b/backend/src/routes/oidc.js index e6963e6..9a9a8d8 100644 --- a/backend/src/routes/oidc.js +++ b/backend/src/routes/oidc.js @@ -2,7 +2,8 @@ * Authentik OIDC SSO routes * * Requires env: - * AUTHENTIK_URL Base URL of your Authentik instance, e.g. https://auth.example.com + * AUTHENTIK_URL Issuer URL of your Authentik application, e.g. + * https://auth.example.com/application/o/sloth-manager * AUTHENTIK_CLIENT_ID OAuth2 application client ID * AUTHENTIK_CLIENT_SECRET OAuth2 application client secret * @@ -26,7 +27,9 @@ async function getDiscovery() { if (_discovery && Date.now() - _discoveryTime < DISCOVERY_TTL_MS) return _discovery; const base = (process.env.AUTHENTIK_URL || '').replace(/\/$/, ''); if (!base) throw new Error('AUTHENTIK_URL is not configured'); - const res = await fetch(`${base}/application/o/.well-known/openid-configuration`); + // AUTHENTIK_URL is the issuer URL, e.g. https://auth.example.com/application/o/sloth-manager + // Authentik discovery doc lives at /.well-known/openid-configuration + const res = await fetch(`${base}/.well-known/openid-configuration`); if (!res.ok) throw new Error(`Authentik discovery fetch failed: HTTP ${res.status}`); _discovery = await res.json(); _discoveryTime = Date.now();