Adds the heph-pwa redirect URIs to the Authentik `heph` OAuth2 provider so the new browser **Login with Authentik** flow (Authorization Code + PKCE, hephaestus PR #9) can redirect back and exchange the code: - `https://heph.ops.eblu.me/` (the PWA origin) - `http://localhost:8787/` (local dev: `hephd --web-root`) Authentik also keys token-endpoint CORS off these origins, so they're required for the browser token exchange. Additive (the provider was `redirect_uris: []`); harmless until the PWA feature deploys. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Reviewed-on: #370 |
||
|---|---|---|
| .. | ||
| +external-secrets-main-sha-rebuild.infra.md | ||
| +external-secrets-stable-main-sha.infra.md | ||
| +tailscale-operator-mirror-tailnet-url.bugfix.md | ||
| .gitkeep | ||
| external-secrets-ringtail-nix.infra.md | ||
| heph-indri-hub.infra.md | ||
| heph-pwa-redirect-uris.infra.md | ||
| local-external-secrets.infra.md | ||
| reviews-jun4.doc.md | ||
| reviews-jun4.infra.md | ||