Compare commits

..

2 Commits

Author SHA1 Message Date
aiyimickey 14c75a8942 chore: .env.example 统一为本地开发配置(JWT_SECRET/AUTHELIA_URL/COOKIE_DOMAIN) 2026-07-03 14:01:38 +08:00
aiyimickey aa44104095 fix: OA退出登录重定向修复 + SSO切换账号按钮 + 生产配置模板
- logout route 使用 request.url.origin 动态获取 base URL
- 登录页添加「使用其他账号登录」按钮
- 新增 config/.env.prod 生产环境配置模板
2026-07-03 12:12:06 +08:00
4 changed files with 28 additions and 9 deletions

View File

@ -1,15 +1,14 @@
# OA 门户环境变量
# OA 门户环境变量(本地开发)
LDAP_URL=ldap://localhost:3890
LDAP_BASE_DN=dc=tlyq,dc=ai
LDAP_ADMIN_DN=uid=admin,ou=people,dc=tlyq,dc=ai
JWT_SECRET=change-me-same-across-all-sites
JWT_SECRET=dev-jwt-secret-local
COOKIE_DOMAIN=
NODE_ENV=development
# ⚠️ 仅限本地开发环境(自签名证书),生产环境禁止设置此变量
NODE_TLS_REJECT_UNAUTHORIZED=0
# OIDC 配置SSO 统一认证)
AUTHELIA_URL=https://sso.tlyq.ai
# OIDC 配置
AUTHELIA_URL=http://127.0.0.1:6180
OIDC_CLIENT_ID=oa-oidc
OIDC_CLIENT_SECRET=change-me-to-hashed-secret
OIDC_REDIRECT_URI=http://localhost:6179/api/auth/callback
OIDC_CLIENT_SECRET=<见 Authelia 配置>
OIDC_REDIRECT_URI=http://127.0.0.1:6179/api/auth/callback

13
config/.env.prod Normal file
View File

@ -0,0 +1,13 @@
# OA 生产环境配置(模板)
# 真实密钥由首次部署时生成,后续部署不覆盖
LDAP_URL=ldap://lldap:3890
LDAP_BASE_DN=dc=tlyq,dc=ai
LDAP_ADMIN_DN=uid=admin,ou=people,dc=tlyq,dc=ai
JWT_SECRET=__JWT_SECRET__
COOKIE_DOMAIN=.tlyq.ai
NODE_ENV=production
NODE_TLS_REJECT_UNAUTHORIZED=0
AUTHELIA_URL=https://sso.tlyq.ai
OIDC_CLIENT_ID=oa-oidc
OIDC_CLIENT_SECRET=__OIDC_CLIENT_SECRET__
OIDC_REDIRECT_URI=https://oa.tlyq.ai/api/auth/callback

View File

@ -1,7 +1,7 @@
import { NextResponse } from 'next/server'
import { cookies } from 'next/headers'
export async function POST() {
export async function POST(request: Request) {
const cookieStore = await cookies()
const domain = process.env.COOKIE_DOMAIN || ''
@ -12,5 +12,7 @@ export async function POST() {
// Authelia 4.38 不支持 end_session_endpoint直接跳转登录页
// Authelia session 会在 cookie 过期后自动清除
return NextResponse.redirect(new URL('/login', process.env.NEXT_PUBLIC_URL || 'http://127.0.0.1:6179'))
// 从请求 URL 动态获取 base URL避免硬编码 localhost
const { origin } = new URL(request.url)
return NextResponse.redirect(new URL('/login', origin))
}

View File

@ -52,6 +52,11 @@ function LoginPageContent() {
</button>
<p className="text-center text-xs text-slate-400 mb-3"> SSO </p>
<p className="text-center mb-2">
<button onClick={() => { window.location.href = '/api/auth/login/oidc?switch=1' }} className="text-xs text-slate-400 hover:text-slate-600 underline">
使
</button>
</p>
<p className="text-center">
<button onClick={() => setShowLdapForm(true)} className="text-xs text-slate-400 hover:text-slate-600 underline">
使 LDAP