Ralf Haferkamp and Ralf Haferkamp
6dde2839df
fix(oidc_auth): Fix userinfo cache expiration logic
...
When the userinfo claims store in the usercache is found to be expired,
do not return an error but ignore the cached entry and force a
re-verification of the access token (either via parsing the JWT again or
via a UserInfo lookup).
This is required for setups with non-JWT access tokes where the expiry
date set in the cached claims does not reflect the actual token expiry,
but just the CacheTTL.
Fixes : #1493
2026-02-19 13:17:17 +01:00
Ralf Haferkamp and Ralf Haferkamp
212846f2f4
fix(idp): Remove kpop dependency
...
The built package (https://download.kopano.io/community/kapp:/kpop-2.7.2.tgz )
seems to be no longer available and upstream lico already switched away
from it quite a while ago.
Fixes : #2364
2026-02-19 12:16:30 +01:00
opencloudeu
4447893aeb
[tx] updated from transifex
2026-02-18 00:15:57 +00:00
Alex and GitHub
cdb942a093
feat: app-registry adjust default mime-types ( #2354 )
2026-02-17 16:39:55 +01:00
Ralf Haferkamp and Ralf Haferkamp
78703806e4
feat(webfinger): add fallbacks for CLIENT_ID and SCOPE setting
...
This adds the variables 'OC_OIDC_CLIENT_ID' and
'OC_OIDC_CLIENT_SCOPES' as fallbacks for the platform specific settings.
For backwards compatibility with the "old" settings for the 'web'
service we also allow 'WEB_OIDC_CLIENT_ID' and 'WEB_OIDC_SCOPE' for the
"web" platform.
2026-02-17 10:41:35 +01:00
Ralf Haferkamp and Ralf Haferkamp
4f1aca6d90
feat(webfinger): use webfinger properties instead new relations
...
This works the previous commits so that clients can add an addtional
'platform' query parameter to the webfinger request that can be used
to query the oidc client id and list of scopes that the clients need
to use when connecting to the IDP.
This also removes the non-standard issuer relatation introduced in a
previous commit as we can just introduce new relations in the
http://openid.net name space.
For IDP like Authentik that create a separate issuer url per Client
(Application in Authentik's terms) it is suggested to just configure
as single Client and use that id for all platforms (i.e. setting
'WEBFINGER_ANDROID_OIDC_CLIENT_ID', 'WEBFINGER_DESKTOP_OIDC_CLIENT_ID',
'WEBFINGER_IOS_OIDC_CLIENT_ID' and 'WEBFINGER_WEB_OIDC_CLIENT_ID' to
same value.
Related: #2088
Related: https://github.com/opencloud-eu/desktop/issues/246
2026-02-17 10:41:35 +01:00
Ralf Haferkamp and Ralf Haferkamp
24aaeb46ba
chore(webfinger): Simplify weird Query parameter extraction loop
2026-02-17 10:41:35 +01:00
pat-s and Ralf Haferkamp
daeae1f443
feat(webfinger): support desktop and mobile specific OIDC client_id
2026-02-17 10:41:35 +01:00
pat-s and Ralf Haferkamp
84da592c88
feat(webfinger): add desktop-specific OIDC issuer support
2026-02-17 10:41:35 +01:00
opencloudeu
4e9eb596f0
[tx] updated from transifex
2026-02-17 00:17:42 +00:00
Benedikt Kulmann
5be98670f4
chore: bump web to v5.1.0
2026-02-16 11:01:47 +01:00
opencloudeu
e698a35aef
[tx] updated from transifex
2026-02-16 00:16:53 +00:00
opencloudeu
d867665dc1
[tx] updated from transifex
2026-02-15 00:16:35 +00:00
opencloudeu
e0b465342f
[tx] updated from transifex
2026-02-14 00:16:38 +00:00
Thomas Schweiger and GitHub
8f3714f08f
Merge pull request #2333 from opencloud-eu/fix/fix-typo-in-var-description
...
fix: fix typo in variable description
2026-02-12 18:13:02 +01:00
Michael Barz and GitHub
1c493ec46b
fix: include sessionID in sse logout event ( #2327 )
2026-02-12 17:21:09 +01:00
Thomas Schweiger
bac83c4729
fix: fix typo in variable description
2026-02-12 16:48:12 +01:00
Thomas Schweiger
2f7422538b
fix: fix typo in gateway service documentation
2026-02-12 15:43:00 +01:00
opencloudeu
d14ae65eba
[tx] updated from transifex
2026-02-12 00:16:05 +00:00
opencloudeu
1c80721aff
[tx] updated from transifex
2026-02-11 00:15:55 +00:00
Christian Richter and Christian Richter
6f7160556f
fix tests
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-02-10 10:45:09 +01:00
7d5d8f3484
adapt graph service
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
Co-authored-by: Ralf Haferkamp <r.haferkamp@opencloud.eu >
2026-02-10 10:45:09 +01:00
Christian Richter and Christian Richter
5877bfa8a2
initial skel for external tenant id
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-02-10 10:45:09 +01:00
VicDeo and Christian Richter
ab9c4d8f23
Sanitize web config only once
2026-02-09 14:09:33 +01:00
Ralf Haferkamp and Ralf Haferkamp
0639304e96
docs(proxy): Clarify PROXY_OIDC_USERINFO_CACHE_TTL value
...
Try to make it more precise when that value is actually relevant.
Closes : #2252
2026-02-03 15:36:37 +01:00
opencloudeu
7a0bbd93b4
[tx] updated from transifex
2026-02-03 00:14:43 +00:00
opencloudeu
158c920e3d
[tx] updated from transifex
2026-02-01 00:13:47 +00:00
opencloudeu
cad6a61120
[tx] updated from transifex
2026-01-29 00:13:28 +00:00
André Duffeck
e2f6a68810
Do not ever set a TTL for the ID cache. It's not supposed to expire.
2026-01-28 12:52:24 +01:00
opencloudeu
47d5d8c1b8
[tx] updated from transifex
2026-01-28 00:12:56 +00:00
opencloudeu
08a87ad1a3
[tx] updated from transifex
2026-01-27 00:12:45 +00:00
Viktor Scharf and GitHub
6cefc94493
bump-web-5.0.0 ( #2216 )
2026-01-26 15:33:43 +01:00
opencloudeu
0d3fe86873
[tx] updated from transifex
2026-01-26 00:11:58 +00:00
opencloudeu
e372ae0ccf
[tx] updated from transifex
2026-01-25 00:12:01 +00:00
opencloudeu
c43ac9974e
[tx] updated from transifex
2026-01-23 00:12:14 +00:00
opencloudeu
5493a32e3b
[tx] updated from transifex
2026-01-22 00:12:11 +00:00
André Duffeck
80601fc0dc
Do not try to enable multi tenancy for the system storage
2026-01-20 15:49:13 +01:00
Jörn Friedrich Dreyer and GitHub
87ef2d97fa
Clarify what the two requests are used for ( #2179 )
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-01-19 21:38:20 +01:00
opencloudeu
9264617a28
[tx] updated from transifex
2026-01-14 00:09:55 +00:00
Jörn Friedrich Dreyer and GitHub
b7ab1b1f40
Merge pull request #2114 from dragonchaser/consoldiate_log_config
...
consolidate log config in activitylog
2026-01-12 09:50:05 +01:00
opencloudeu
8814f3fa32
[tx] updated from transifex
2026-01-12 00:08:46 +00:00
opencloudeu
f6a54930ea
[tx] updated from transifex
2026-01-09 00:08:53 +00:00
Christian Richter
b51c4af8d9
remove logger from proxytest
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-01-08 14:50:44 +01:00
Christian Richter
cb9815acb1
fix yaml mappings
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-01-08 14:16:31 +01:00
Christian Richter
25952fc27c
consolidate log config in webfinger
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-01-08 13:48:15 +01:00
Christian Richter
36b90c8619
consolidate log config in webdav
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-01-08 13:46:30 +01:00
Christian Richter
f039bcf995
consolidate log config in web
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-01-08 13:44:41 +01:00
Christian Richter
dd34f40618
consolidate log config in users
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-01-08 13:42:54 +01:00
Christian Richter
f69610777d
consolidate log config in userlog
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-01-08 13:41:10 +01:00
Christian Richter
30c4fb2b51
consolidate log config in thumbnails
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-01-08 13:38:14 +01:00