Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
75 lines (64 loc) · 3.72 KB
/
Copy path.env.example
File metadata and controls
75 lines (64 loc) · 3.72 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
# eeID embedded widget demo — configuration.
# cp .env.example .env
# =============================================================================
# Required
# =============================================================================
# ---- Your OAuth2 client (confidential) ----
# The same client credentials you would use for the classic redirect flow. The secret stays
# server-side; it is never sent to the browser.
EEID_CLIENT_ID=CHANGE_ME_client_id
EEID_CLIENT_SECRET=CHANGE_ME_client_secret
# ---- Your eeID login server ----
# The origin the widget is served from. A service lives in exactly one eeID environment — ask
# whoever issued your client credentials which one yours belongs to.
# production https://auth.eeid.ee
# test https://test-auth.eeid.ee
EEID_LOGIN_PUBLIC_URL=https://auth.eeid.ee
# ---- A registered redirect_uri on that client ----
# The browser never navigates there in the embedded flow. It is required because eeID starts a
# real OAuth2 authorization request with it, and the same value is presented again at the token
# exchange, so it must match a registered URI exactly.
EEID_REDIRECT_URI=https://your-app.example/auth/oidc/callback
EEID_SCOPE=openid
EEID_LOCALE=en
# =============================================================================
# IMPORTANT: allowlist this demo's origin
# =============================================================================
# This demo runs at http://localhost:8081. Your eeID service must have embedded mode enabled
# AND that origin allowlisted, or session creation fails with
# 403 Embedded mode is not enabled for this client.
# and the browser refuses to frame the widget.
#
# In the eeID Manager, on the service's edit form:
# - tick "Enable embedded widget"
# - add http://localhost:8081 under "Embedded widget allowed origins" (one per line)
#
# Origins are scheme://host[:port] only — no trailing path, no wildcards.
# =============================================================================
# Optional
# =============================================================================
# ---- Several eeID stacks, probed automatically ----
# eeID can be deployed as more than one independent stack (e.g. Test and Production), and a
# service lives in exactly ONE of them: its OAuth2 client is registered in that stack's OAuth2
# server and removed from the others. Instead of configuring which, list the candidates and the
# demo uses whichever ACCEPTS these credentials — so moving a service between environments needs
# no config change here.
#
# Comma-separated "<login origin>|<OAuth2 server base>", most likely first. The second half is
# where that stack publishes /.well-known/openid-configuration — its own host on some
# deployments, a path prefix on others; omit it and the login origin is tried with the
# /hydra-public prefix. The token endpoint is read from there, so it needs no configuration.
#
# Leave this unset if you use EEID_LOGIN_PUBLIC_URL above (which pins one stack and skips
# probing). Set one or the other — there is no built-in default.
# EEID_ENVIRONMENTS=https://test-auth.eeid.ee,https://auth.eeid.ee
# ---- Private address for the server-side calls ----
# Only when your backend reaches the login server on an address the browser cannot use — e.g. a
# container name on a shared Docker network. Applies alongside a pinned EEID_LOGIN_PUBLIC_URL.
# EEID_LOGIN_INTERNAL_URL=http://eeid-login:3000
# ---- Explicit token endpoint ----
# Only when the OAuth2 server publishes no discovery document under the login origin.
# EEID_HYDRA_TOKEN_URL=https://auth.eeid.ee/hydra-public/oauth2/token
# ---- TLS verification for server-side calls ----
# Set to 0 only against a local stack using a private CA. Never in production.
# EEID_VERIFY_TLS=1