diff --git a/config/.env.prod b/config/.env.prod new file mode 100644 index 0000000..309e841 --- /dev/null +++ b/config/.env.prod @@ -0,0 +1,13 @@ +# OA 生产环境配置(模板) +# 真实密钥由首次部署时生成,后续部署不覆盖 +LDAP_URL=ldap://lldap:3890 +LDAP_BASE_DN=dc=tlyq,dc=ai +LDAP_ADMIN_DN=uid=admin,ou=people,dc=tlyq,dc=ai +JWT_SECRET=__JWT_SECRET__ +COOKIE_DOMAIN=.tlyq.ai +NODE_ENV=production +NODE_TLS_REJECT_UNAUTHORIZED=0 +AUTHELIA_URL=https://sso.tlyq.ai +OIDC_CLIENT_ID=oa-oidc +OIDC_CLIENT_SECRET=__OIDC_CLIENT_SECRET__ +OIDC_REDIRECT_URI=https://oa.tlyq.ai/api/auth/callback \ No newline at end of file diff --git a/src/app/api/auth/logout/route.ts b/src/app/api/auth/logout/route.ts index 8a73281..17195fe 100644 --- a/src/app/api/auth/logout/route.ts +++ b/src/app/api/auth/logout/route.ts @@ -1,7 +1,7 @@ import { NextResponse } from 'next/server' import { cookies } from 'next/headers' -export async function POST() { +export async function POST(request: Request) { const cookieStore = await cookies() const domain = process.env.COOKIE_DOMAIN || '' @@ -12,5 +12,7 @@ export async function POST() { // Authelia 4.38 不支持 end_session_endpoint,直接跳转登录页 // Authelia session 会在 cookie 过期后自动清除 - return NextResponse.redirect(new URL('/login', process.env.NEXT_PUBLIC_URL || 'http://127.0.0.1:6179')) + // 从请求 URL 动态获取 base URL,避免硬编码 localhost + const { origin } = new URL(request.url) + return NextResponse.redirect(new URL('/login', origin)) } diff --git a/src/app/login/page.tsx b/src/app/login/page.tsx index d3a1db0..e0d1cbf 100644 --- a/src/app/login/page.tsx +++ b/src/app/login/page.tsx @@ -52,6 +52,11 @@ function LoginPageContent() { 统一认证登录
通过 SSO 统一身份认证
++ +