fix!: do not allow insecure oauth requests by default (#27844)

* fix!: do not allow insecure oauth requests by default

* fix: format

* fix: make open-api

* fix: tests

* nit: casing

* chore: migration to allow insecure if current oauth uses http
This commit is contained in:
bo0tzz
2026-04-16 16:11:58 +02:00
committed by GitHub
parent 9c642bd6fc
commit 3356e81c85
11 changed files with 77 additions and 3 deletions
+2
View File
@@ -111,6 +111,7 @@ export type SystemConfig = {
profileSigningAlgorithm: string;
tokenEndpointAuthMethod: OAuthTokenEndpointAuthMethod;
timeout: number;
allowInsecureRequests: boolean;
storageLabelClaim: string;
storageQuotaClaim: string;
roleClaim: string;
@@ -305,6 +306,7 @@ export const defaults = Object.freeze<SystemConfig>({
roleClaim: 'immich_role',
tokenEndpointAuthMethod: OAuthTokenEndpointAuthMethod.ClientSecretPost,
timeout: 30_000,
allowInsecureRequests: false,
},
passwordLogin: {
enabled: true,