Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
af11f5119c |
@@ -1,5 +1,4 @@
|
|||||||
VITE_API_BASE_URL=http://localhost:8080
|
VITE_API_BASE_URL=http://localhost:8080
|
||||||
VITE_OAUTH_CLIENT_ID=stalwart-webui
|
|
||||||
#VITE_ACCESS_TOKEN=OPEN_SESAME
|
#VITE_ACCESS_TOKEN=OPEN_SESAME
|
||||||
VITE_OAUTH_SCOPES=
|
VITE_OAUTH_SCOPES=
|
||||||
|
|
||||||
|
|||||||
+9
-14
@@ -12,19 +12,14 @@ dist
|
|||||||
dist-ssr
|
dist-ssr
|
||||||
*.local
|
*.local
|
||||||
|
|
||||||
# Editor directories and files
|
|
||||||
.vscode/*
|
|
||||||
!.vscode/extensions.json
|
|
||||||
.idea
|
|
||||||
.DS_Store
|
|
||||||
*.suo
|
|
||||||
*.ntvs*
|
|
||||||
*.njsproj
|
|
||||||
*.sln
|
|
||||||
*.sw?
|
|
||||||
.ignore
|
.ignore
|
||||||
scripts/
|
scripts/
|
||||||
*.md
|
|
||||||
!README.md
|
.*
|
||||||
!CHANGELOG.md
|
!.gitignore
|
||||||
/SPEC-*
|
!.prettierrc
|
||||||
|
!.env.development
|
||||||
|
!.github/
|
||||||
|
!.vscode/
|
||||||
|
.vscode/*
|
||||||
|
!.vscode/extensions.json
|
||||||
|
|||||||
@@ -2,6 +2,15 @@
|
|||||||
|
|
||||||
All notable changes to this project will be documented in this file. This project adheres to [Semantic Versioning](http://semver.org/).
|
All notable changes to this project will be documented in this file. This project adheres to [Semantic Versioning](http://semver.org/).
|
||||||
|
|
||||||
|
## [1.0.9] - 2026-08-24
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- Server configurable OAuth client ID.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
## [1.0.8] - 2026-07-31
|
## [1.0.8] - 2026-07-31
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|||||||
@@ -71,7 +71,6 @@ Configuration is done through Vite environment variables. Copy or edit `.env.dev
|
|||||||
|
|
||||||
```
|
```
|
||||||
VITE_API_BASE_URL=http://localhost:443
|
VITE_API_BASE_URL=http://localhost:443
|
||||||
VITE_OAUTH_CLIENT_ID=stalwart-webui
|
|
||||||
VITE_ACCESS_TOKEN=
|
VITE_ACCESS_TOKEN=
|
||||||
VITE_OAUTH_SCOPES=
|
VITE_OAUTH_SCOPES=
|
||||||
```
|
```
|
||||||
@@ -79,10 +78,20 @@ VITE_OAUTH_SCOPES=
|
|||||||
| Variable | Description |
|
| Variable | Description |
|
||||||
|---|---|
|
|---|---|
|
||||||
| `VITE_API_BASE_URL` | URL of the Stalwart server. Used for all API requests during development. In production builds (when empty or unset) requests are relative to the current origin. |
|
| `VITE_API_BASE_URL` | URL of the Stalwart server. Used for all API requests during development. In production builds (when empty or unset) requests are relative to the current origin. |
|
||||||
| `VITE_OAUTH_CLIENT_ID` | OAuth 2.0 client ID. Defaults to `stalwart-webui`. |
|
|
||||||
| `VITE_ACCESS_TOKEN` | When set, skips the OAuth flow entirely and uses this token for all requests. Useful for local development and testing. |
|
| `VITE_ACCESS_TOKEN` | When set, skips the OAuth flow entirely and uses this token for all requests. Useful for local development and testing. |
|
||||||
| `VITE_OAUTH_SCOPES` | Optional OAuth scopes. Omitted from the authorization request when empty. |
|
| `VITE_OAUTH_SCOPES` | Optional OAuth scopes. Omitted from the authorization request when empty. |
|
||||||
|
|
||||||
|
### OAuth client ID
|
||||||
|
|
||||||
|
The OAuth 2.0 client ID is not a build-time setting. It is read at runtime from a meta tag in `index.html`:
|
||||||
|
|
||||||
|
```html
|
||||||
|
<meta name="oauth-client-id" content="" />
|
||||||
|
```
|
||||||
|
|
||||||
|
The server rewrites the `content` attribute when it serves the page, so a single build works for any deployment. When no
|
||||||
|
client ID is configured the attribute is left empty and the panel falls back to `stalwart-webui`.
|
||||||
|
|
||||||
### Bypassing OAuth for development
|
### Bypassing OAuth for development
|
||||||
|
|
||||||
Set `VITE_ACCESS_TOKEN` to a valid bearer token to skip the login page and go straight to the admin panel. You can obtain a token from the Stalwart server's token endpoint or use an API key:
|
Set `VITE_ACCESS_TOKEN` to a valid bearer token to skip the login page and go straight to the admin panel. You can obtain a token from the Stalwart server's token endpoint or use an API key:
|
||||||
|
|||||||
@@ -4,6 +4,7 @@
|
|||||||
<head>
|
<head>
|
||||||
<meta charset="UTF-8" />
|
<meta charset="UTF-8" />
|
||||||
<base href="/" />
|
<base href="/" />
|
||||||
|
<meta name="oauth-client-id" content="" />
|
||||||
<link rel="icon" type="image/x-icon" href="favicon.ico" />
|
<link rel="icon" type="image/x-icon" href="favicon.ico" />
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||||
<title>Portal</title>
|
<title>Portal</title>
|
||||||
|
|||||||
+1
-1
@@ -1,7 +1,7 @@
|
|||||||
{
|
{
|
||||||
"name": "stalwart-webui",
|
"name": "stalwart-webui",
|
||||||
"private": true,
|
"private": true,
|
||||||
"version": "1.0.8",
|
"version": "1.0.9",
|
||||||
"description": "Stalwart WebUI",
|
"description": "Stalwart WebUI",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
|
|||||||
@@ -0,0 +1,56 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*/
|
||||||
|
|
||||||
|
import { describe, it, expect, afterEach, vi } from 'vitest';
|
||||||
|
|
||||||
|
const originalHead = document.head.innerHTML;
|
||||||
|
|
||||||
|
async function loadWithMeta(meta: string) {
|
||||||
|
document.head.innerHTML = meta;
|
||||||
|
vi.resetModules();
|
||||||
|
const { getOAuthClientId } = await import('./oauthClientId');
|
||||||
|
return getOAuthClientId;
|
||||||
|
}
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
document.head.innerHTML = originalHead;
|
||||||
|
vi.resetModules();
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('getOAuthClientId', () => {
|
||||||
|
it('prefers the client id injected by the server', async () => {
|
||||||
|
const getOAuthClientId = await loadWithMeta('<meta name="oauth-client-id" content="pocket-id-client" />');
|
||||||
|
expect(getOAuthClientId()).toBe('pocket-id-client');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('trims surrounding whitespace from the injected client id', async () => {
|
||||||
|
const getOAuthClientId = await loadWithMeta('<meta name="oauth-client-id" content=" pocket-id-client " />');
|
||||||
|
expect(getOAuthClientId()).toBe('pocket-id-client');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('falls back to the built-in default when the placeholder is empty', async () => {
|
||||||
|
const getOAuthClientId = await loadWithMeta('<meta name="oauth-client-id" content="" />');
|
||||||
|
expect(getOAuthClientId()).toBe('stalwart-webui');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('falls back to the built-in default when the placeholder is only whitespace', async () => {
|
||||||
|
const getOAuthClientId = await loadWithMeta('<meta name="oauth-client-id" content=" " />');
|
||||||
|
expect(getOAuthClientId()).toBe('stalwart-webui');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('falls back to the built-in default when the placeholder is absent', async () => {
|
||||||
|
const getOAuthClientId = await loadWithMeta('');
|
||||||
|
expect(getOAuthClientId()).toBe('stalwart-webui');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('reads the document only once', async () => {
|
||||||
|
const getOAuthClientId = await loadWithMeta('<meta name="oauth-client-id" content="pocket-id-client" />');
|
||||||
|
expect(getOAuthClientId()).toBe('pocket-id-client');
|
||||||
|
|
||||||
|
document.head.innerHTML = '<meta name="oauth-client-id" content="changed-later" />';
|
||||||
|
expect(getOAuthClientId()).toBe('pocket-id-client');
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*/
|
||||||
|
|
||||||
|
const DEFAULT_CLIENT_ID = 'stalwart-webui';
|
||||||
|
|
||||||
|
let cached: string | undefined;
|
||||||
|
|
||||||
|
export function getOAuthClientId(): string {
|
||||||
|
if (cached !== undefined) return cached;
|
||||||
|
|
||||||
|
const injected = document.querySelector('meta[name="oauth-client-id"]')?.getAttribute('content')?.trim();
|
||||||
|
cached = injected ? injected : DEFAULT_CLIENT_ID;
|
||||||
|
return cached;
|
||||||
|
}
|
||||||
+2
-1
@@ -6,6 +6,7 @@
|
|||||||
|
|
||||||
import { useAuthStore } from '../stores/authStore';
|
import { useAuthStore } from '../stores/authStore';
|
||||||
import { getBasePath } from '@/lib/basePath';
|
import { getBasePath } from '@/lib/basePath';
|
||||||
|
import { getOAuthClientId } from '@/lib/oauthClientId';
|
||||||
|
|
||||||
export function getApiBaseUrl(): string {
|
export function getApiBaseUrl(): string {
|
||||||
const envUrl = import.meta.env.VITE_API_BASE_URL as string | undefined;
|
const envUrl = import.meta.env.VITE_API_BASE_URL as string | undefined;
|
||||||
@@ -45,7 +46,7 @@ export async function refreshAccessToken(): Promise<void> {
|
|||||||
throw new Error('No refresh token or token endpoint available');
|
throw new Error('No refresh token or token endpoint available');
|
||||||
}
|
}
|
||||||
|
|
||||||
const clientId = (import.meta.env.VITE_OAUTH_CLIENT_ID as string) || 'stalwart-webui';
|
const clientId = getOAuthClientId();
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const response = await fetch(tokenEndpoint, {
|
const response = await fetch(tokenEndpoint, {
|
||||||
|
|||||||
@@ -6,9 +6,9 @@
|
|||||||
|
|
||||||
import { getApiBaseUrl } from '@/services/api';
|
import { getApiBaseUrl } from '@/services/api';
|
||||||
import { getBasePath } from '@/lib/basePath';
|
import { getBasePath } from '@/lib/basePath';
|
||||||
|
import { getOAuthClientId } from '@/lib/oauthClientId';
|
||||||
import i18n from '@/i18n';
|
import i18n from '@/i18n';
|
||||||
|
|
||||||
const CLIENT_ID = (import.meta.env.VITE_OAUTH_CLIENT_ID as string) || 'stalwart-webui';
|
|
||||||
const SCOPES = import.meta.env.VITE_OAUTH_SCOPES as string | undefined;
|
const SCOPES = import.meta.env.VITE_OAUTH_SCOPES as string | undefined;
|
||||||
|
|
||||||
const SESSION_PREFIX = 'stalwart-oauth-';
|
const SESSION_PREFIX = 'stalwart-oauth-';
|
||||||
@@ -97,7 +97,7 @@ export async function exchangeCode(
|
|||||||
grant_type: 'authorization_code',
|
grant_type: 'authorization_code',
|
||||||
code,
|
code,
|
||||||
code_verifier: codeVerifier,
|
code_verifier: codeVerifier,
|
||||||
client_id: CLIENT_ID,
|
client_id: getOAuthClientId(),
|
||||||
redirect_uri: redirectUri,
|
redirect_uri: redirectUri,
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -153,7 +153,7 @@ export async function startAuthFlow(username: string, returnUrl?: string | null)
|
|||||||
|
|
||||||
const params = new URLSearchParams({
|
const params = new URLSearchParams({
|
||||||
response_type: 'code',
|
response_type: 'code',
|
||||||
client_id: CLIENT_ID,
|
client_id: getOAuthClientId(),
|
||||||
redirect_uri: getRedirectUri(),
|
redirect_uri: getRedirectUri(),
|
||||||
code_challenge: codeChallenge,
|
code_challenge: codeChallenge,
|
||||||
code_challenge_method: codeChallengeMethod,
|
code_challenge_method: codeChallengeMethod,
|
||||||
@@ -206,7 +206,7 @@ export function getPostLogoutRedirectUri(): string {
|
|||||||
|
|
||||||
export function buildEndSessionUrl(endSessionEndpoint: string, postLogoutRedirectUri: string): string {
|
export function buildEndSessionUrl(endSessionEndpoint: string, postLogoutRedirectUri: string): string {
|
||||||
const params = new URLSearchParams({
|
const params = new URLSearchParams({
|
||||||
client_id: CLIENT_ID,
|
client_id: getOAuthClientId(),
|
||||||
post_logout_redirect_uri: postLogoutRedirectUri,
|
post_logout_redirect_uri: postLogoutRedirectUri,
|
||||||
});
|
});
|
||||||
const sep = endSessionEndpoint.includes('?') ? '&' : '?';
|
const sep = endSessionEndpoint.includes('?') ? '&' : '?';
|
||||||
|
|||||||
Vendored
-1
@@ -8,7 +8,6 @@
|
|||||||
|
|
||||||
interface ImportMetaEnv {
|
interface ImportMetaEnv {
|
||||||
readonly VITE_API_BASE_URL: string;
|
readonly VITE_API_BASE_URL: string;
|
||||||
readonly VITE_OAUTH_CLIENT_ID: string;
|
|
||||||
readonly VITE_ACCESS_TOKEN: string;
|
readonly VITE_ACCESS_TOKEN: string;
|
||||||
readonly VITE_OAUTH_SCOPES: string;
|
readonly VITE_OAUTH_SCOPES: string;
|
||||||
readonly VITE_DEBUG_JMAP?: string;
|
readonly VITE_DEBUG_JMAP?: string;
|
||||||
|
|||||||
Reference in New Issue
Block a user