blumeops/docs/changelog.d
Erich Blume 50a36ff93a heph Authentik: grant offline_access scope (fixes spoke sync refresh-token 400)
The heph CLI requests scope "openid offline_access", but the Authentik
heph OAuth2 provider only mapped openid/email/profile. Without the
offline_access mapping the issued refresh token is bound to the login
session rather than the 30-day refresh-token window; once the session
lapses, hephd's refresh_token grant returns 400 Bad Request and spoke
sync silently degrades (heph sync --status -> auth_failure: true).

Add the built-in offline_access scope mapping to the provider's
property_mappings and document the requirement in the service reference.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-06 18:07:13 -07:00
..
+external-secrets-main-sha-rebuild.infra.md C0: rebuild external-secrets image off main (v2.2.0-0e70a1b) 2026-06-04 14:59:17 -07:00
+external-secrets-stable-main-sha.infra.md C0: rebuild external-secrets off main, repoint both clusters to stable tags 2026-06-04 16:19:20 -07:00
+heph-hub-v1.2.1.infra.md C0: bump indri heph hub to v1.2.1 (PWA Authentik login + /config) 2026-06-05 07:40:51 -07:00
+tailscale-operator-mirror-tailnet-url.bugfix.md C0: point tailscale-operator base mirror fetch at tailnet forge 2026-06-04 12:40:21 -07:00
.gitkeep Add towncrier changelog system (#86) 2026-02-03 11:48:13 -08:00
external-secrets-ringtail-nix.infra.md Localize external-secrets on ringtail (amd64 nix build) (#368) 2026-06-04 15:37:42 -07:00
heph-indri-hub.infra.md Add hephaestus sync hub to indri (launchagent, PWA, device-code OIDC) (#369) 2026-06-05 06:46:58 -07:00
heph-offline-access.bugfix.md heph Authentik: grant offline_access scope (fixes spoke sync refresh-token 400) 2026-06-06 18:07:13 -07:00
heph-pwa-redirect-uris.infra.md heph Authentik: register heph-pwa redirect URIs (PKCE login) (#370) 2026-06-05 07:30:31 -07:00
local-external-secrets.infra.md Localize external-secrets container (native container.py build) (#367) 2026-06-04 14:55:55 -07:00
reviews-jun4.doc.md Recurring review sweep: 4 doc cards + nvidia-device-plugin v0.19.2 (#366) 2026-06-04 13:37:02 -07:00
reviews-jun4.infra.md Recurring review sweep: 4 doc cards + nvidia-device-plugin v0.19.2 (#366) 2026-06-04 13:37:02 -07:00