atlas
8c51e37804
swarm-authelia: let a client declare its token-endpoint auth method
...
tuwunel authenticates at the token endpoint with the secret in the POST
body. Authelia enforces the method a client is REGISTERED with rather
than accepting whichever one arrives, and its default is
client_secret_basic — so the matrix login completed, consent was
granted, and the very last hop failed:
Client authentication failed ... The request was determined to be
using token_endpoint_auth_method client_secret_post, however the
OAuth 2.0 client registration does not allow this method.
The failure names neither the secret nor the redirect, and it lands
three layers from its cause, which is why it read as a credential
problem.
Adds a per-client tokenEndpointAuthMethod, null by default so every
existing client keeps authelia default (forgejo authenticates with
basic and is unaffected), and sets client_secret_post on the matrix
client only.
2026-08-16 17:48:52 +02:00
..
hive-c0re
feat(swarm): wire a hive's queue coordinates for status publishing
2026-08-16 13:14:03 +02:00
hive-forge
fix(hive-forge): give the SSO-source unit the same TLS trust as forgejo
2026-08-15 22:01:46 +02:00
hive-gateway
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
lib
feat(nix): issue each hive's CA under a swarm root CA
2026-08-05 15:57:50 +02:00
default.nix
feat(3112): the swarm-nats container, fail-closed
2026-08-14 16:26:12 +02:00
hive-ci.nix
feat(nix): move the forge host options under services.hyperhive.swarm
2026-08-05 03:44:53 +02:00
hive-matrix.nix
swarm-authelia: let a client declare its token-endpoint auth method
2026-08-16 17:48:52 +02:00
hive-network.nix
docs(3191): the gateway's comments describe a host service, not a container
2026-08-12 12:20:28 +02:00
hive-priv.nix
fix( #2573 ): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class)
2026-07-18 16:39:20 +02:00
hive-tls.nix
docs(3191): drop the migration history from the gateway comments
2026-08-12 13:26:58 +02:00
hyperhive.nix
refactor(nix): a hive's domain comes out of the swarm directory
2026-08-05 22:43:17 +02:00
local-defaults.nix
feat(swarm-nats): mint the auth-callout nkeys on all-local hives
2026-08-16 15:59:06 +02:00
otel.nix
docs(otel): validateConfigFile is a parser, not a wiring check
2026-08-15 12:13:48 +02:00
swarm-authelia.nix
swarm-authelia: let a client declare its token-endpoint auth method
2026-08-16 17:48:52 +02:00
swarm-ca.nix
fix(nix): a missing swarm-services leaf must not kill the whole gateway
2026-08-06 00:30:22 +02:00
swarm-controller.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-nats.nix
swarm-nats: cut the comments back to what the code cannot say
2026-08-16 16:19:30 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
refactor(nix): make all-local a deployment mode, not a default
2026-08-05 19:41:11 +02:00
swarm-snapshot-store.nix
refactor( #2862 ): keep the option at services.hyperhive.snapshotStore
2026-07-31 19:03:24 +02:00
swarm-ui.nix
swarm-controller: serve swarm-wide service quick links (hyperhive#3289)
2026-08-15 14:24:52 +02:00
swarm-wireguard.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm.nix
feat(swarm): wire a hive's queue coordinates for status publishing
2026-08-16 13:14:03 +02:00