Adds native OpenID Connect login alongside the existing LDAP and forward-auth modes. Two new TA_LOGIN_AUTH_MODE values: oidc (SSO only) and oidc_local (SSO + local break-glass), mirroring ldap/ldap_local. TAOIDCBackend maps OIDC claims onto the Account model (USERNAME_FIELD is name) and promotes staff/superuser from a configurable group claim, like the LDAP backend. The redirect_uri is anchored to TA_HOST so it stays correct behind nginx and a TLS-terminating proxy; PKCE and audience verification are on. The login page gains a "Log in with SSO" button driven by a public /api/user/oidc/ endpoint, hidden in oidc-only mode. API token auth is unaffected. Configured entirely via TA_OIDC_* env vars. Tested against Authentik. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| appsettings | ||
| channel | ||
| common | ||
| config | ||
| download | ||
| playlist | ||
| stats | ||
| task | ||
| user | ||
| video | ||
| README.md | ||
| manage.py | ||
| requirements.txt | ||
README.md
Django Setup
Apps
The backend is split up into the following apps.
config
Root Django App. Doesn't define any views.
- Has main
settings.py - Has main
urls.pyresponsible for routing to other apps
common
Functionality shared between apps.
Defines views on the root /api/* path. Has base views to inherit from.
- Connections to ES and Redis
- Searching
- URL parser
- Collection of helper functions
appsettings
Responsible for functionality from the settings pages.
Defines views at /api/appsettings/*.
- Index setup
- Reindexing
- Snapshots
- Filesystem Scan
- Manual import
channel
Responsible for Channel Indexing functionality.
Defines views at /api/channel/* path.
download
Implements download functionality with yt-dlp.
Defines views at /api/download/*.
- Download videos
- Queue management
- Thumbnails
- Subscriptions
playlist
Implements playlist functionality.
Defines views at /api/playlist/*.
- Index Playlists
- Manual Playlists
stats
Builds aggregations views for the statistics dashboard.
Defines views at /api/stats/*.
task
Defines tasks for Celery.
Defines views at /api/task/*.
- Has main
tasks.pywith all shared_task definitions - Has
CustomPeriodicTaskmodel - Implements apprise notifications links
- Implements schedule functionality
user
Implements user and auth functionality.
Defines views at /api/config/*.
- Defines custom
Accountmodel
video
Index functionality for videos.
Defines views at /api/video/*.
- Index videos
- Index comments
- Index/download subtitles
- Media stream parsing