diff --git a/clients/quadraticserver/searxng.nix b/clients/quadraticserver/searxng.nix index 2cbd6c5..1d6865e 100644 --- a/clients/quadraticserver/searxng.nix +++ b/clients/quadraticserver/searxng.nix @@ -45,12 +45,10 @@ route { jwtauth { - from_header Authorization + from_cookies id_token sign_key {$JWK_SECRET} - sign_alg HS256 issuer_whitelist ${auth} audience_whitelist proxy - user_claims sub } reverse_proxy unix/${socket} diff --git a/flake.lock b/flake.lock index caa872e..aac8067 100644 --- a/flake.lock +++ b/flake.lock @@ -624,11 +624,11 @@ ] }, "locked": { - "lastModified": 1750616153, - "narHash": "sha256-EpOssz6cLEep63pBuOR8jAW9v6hxjytgWVjGIhac8VQ=", + "lastModified": 1750620651, + "narHash": "sha256-MqmzdsKUrOTN8NhjuldA1GHMgVsWsBmtMgHzpiSWnn0=", "ref": "refs/heads/main", - "rev": "32ec721e23606a6ce0616441b0a22a8300e59a92", - "revCount": 25, + "rev": "13a469ba6dfbb1ef6431570b952fb4a78471e63f", + "revCount": 28, "type": "git", "url": "https://git.federated.nexus/Henry-Hiles/matrixoidc" }, diff --git a/secrets/oidcJwtSecretEnv.age b/secrets/oidcJwtSecretEnv.age index 044ab9e..a57376c 100644 --- a/secrets/oidcJwtSecretEnv.age +++ b/secrets/oidcJwtSecretEnv.age @@ -1,9 +1,11 @@ -----BEGIN AGE ENCRYPTED FILE----- -YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IFZLUVVkUSAvc0Js -TkdoaHNQY2JKK3liaWZRTjUrVmJqbWRUZHdTRlJ5emE3bXJCTEFvCitBL0MwazVD -TDV0eThLU2ttOXBVQkFqWFVjbjViMllJYngrODZPRjZuaFUKLT4gIy1ncmVhc2Ug -azFQKSB2dyRBeXAuaSAvICdESU4zO1MKQmxFeWhXZ1oKLS0tIFFuNjRuN2g0TXIx -eHlSbGI0c0MxLzdMWVY3S21jbzgreHQwd2dFUzJuYlEKWCr+LzEM1dxB3+E3TFfX -uWJOgQOc6SKNutMSrSw7G/RJZev3EBp9NkJvdSbrSYEVzv3FEUytZFV7EfC9TmXR -WoabHyMxaZ0I6IdV0FYaGVQPBf4PT5FPyLKAkWF9bjHBvtwxOCJ+/XT1bzBRLRk= +YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IFZLUVVkUSBYdDJD +NWJNcVUvd0JmTDhVZEVzck12ek1iTlpCREVPYVZ6Y0lhM1VBZmxBCkFwZmU2R3BG +Y0VIcllFUlU1VjZVNDB1eFZ2eFBpMDBLWUVSODlrU0R2VnMKLT4gUlpkLWdyZWFz +ZSAvdF89IEo5LQpVNVcwc2JmZWdUalJrWVNEQXAzQkh1UFJGTzdDeU5HdDdrTnZu +VXFvQ2dnemN0eDFGNnpsU21jMlBrZFNyL0o0CmpYTHFuS2VpdHcKLS0tIE9FZHo5 +dlZtOXNVaUIrUVlxM0lWcGFzc1k3MVhTam9vbzF1ZnExVzd4Qm8KGMrtis7WGy6p +IToPtJLsWzxnQKeD4MMLNfH6PTI0CbPqwBwdjEGjWe6CBENbxsgLL/Ggs3JIDjHI +aYXh7La2fwl1TkVGhOshspT0a7gdRhWJexdVHEUy/qNQyqrpl41r0UW4ZMXwF6bm +ztXlKgSjV8SuFKNzpyMPUEtO7CFkLLPlwxor6CI= -----END AGE ENCRYPTED FILE-----