This commit is contained in:
2025-09-12 19:16:33 +03:00
parent 4c05645a50
commit 2397cd1090

View File

@@ -132,9 +132,8 @@ in
serviceConfig = {
LoadCredential = ["client-secret:${oauthClientSecretFP}"];
ExecStart = lib.mkForce (pkgs.writeShellScript "run-mastodon-with-client-secret" ''
export CLIENT_SECRET=$(cat $CREDENTIALS_DIRECTORY/client-secret)
echo -n $CLIENT_SECRET # TODO: debug only option
CLIENT_SECRET=$(cat $CREDENTIALS_DIRECTORY/client-secret) ${config.services.mastodon.package}/bin/puma -C config/puma.rb
export OIDC_CLIENT_SECRET=$(cat $CREDENTIALS_DIRECTORY/client-secret)
${config.services.mastodon.package}/bin/puma -C config/puma.rb
'');
};
environment = {
@@ -143,7 +142,6 @@ in
OIDC_ENABLED = "true";
OIDC_DISPLAY_NAME= "Kanidm";
OIDC_ISSUER = issuer;
# OIDC_ISSUER = "https://auth.hollowness.top";
OIDC_DISCOVERY = "true";
OIDC_SCOPE = "openid,profile";
OIDC_UID_FIELD = "sub";