1 Commits
Author SHA1 Message Date
Maurus Decimus af11f5119c v1.0.9 2026-08-24 15:44:51 +02:00
11 changed files with 110 additions and 24 deletions
-1
View File
@@ -1,5 +1,4 @@
VITE_API_BASE_URL=http://localhost:8080 VITE_API_BASE_URL=http://localhost:8080
VITE_OAUTH_CLIENT_ID=stalwart-webui
#VITE_ACCESS_TOKEN=OPEN_SESAME #VITE_ACCESS_TOKEN=OPEN_SESAME
VITE_OAUTH_SCOPES= VITE_OAUTH_SCOPES=
+9 -14
View File
@@ -12,19 +12,14 @@ dist
dist-ssr dist-ssr
*.local *.local
# Editor directories and files
.vscode/*
!.vscode/extensions.json
.idea
.DS_Store
*.suo
*.ntvs*
*.njsproj
*.sln
*.sw?
.ignore .ignore
scripts/ scripts/
*.md
!README.md .*
!CHANGELOG.md !.gitignore
/SPEC-* !.prettierrc
!.env.development
!.github/
!.vscode/
.vscode/*
!.vscode/extensions.json
+9
View File
@@ -2,6 +2,15 @@
All notable changes to this project will be documented in this file. This project adheres to [Semantic Versioning](http://semver.org/). All notable changes to this project will be documented in this file. This project adheres to [Semantic Versioning](http://semver.org/).
## [1.0.9] - 2026-08-24
### Added
- Server configurable OAuth client ID.
### Changed
### Fixed
## [1.0.8] - 2026-07-31 ## [1.0.8] - 2026-07-31
### Added ### Added
+11 -2
View File
@@ -71,7 +71,6 @@ Configuration is done through Vite environment variables. Copy or edit `.env.dev
``` ```
VITE_API_BASE_URL=http://localhost:443 VITE_API_BASE_URL=http://localhost:443
VITE_OAUTH_CLIENT_ID=stalwart-webui
VITE_ACCESS_TOKEN= VITE_ACCESS_TOKEN=
VITE_OAUTH_SCOPES= VITE_OAUTH_SCOPES=
``` ```
@@ -79,10 +78,20 @@ VITE_OAUTH_SCOPES=
| Variable | Description | | Variable | Description |
|---|---| |---|---|
| `VITE_API_BASE_URL` | URL of the Stalwart server. Used for all API requests during development. In production builds (when empty or unset) requests are relative to the current origin. | | `VITE_API_BASE_URL` | URL of the Stalwart server. Used for all API requests during development. In production builds (when empty or unset) requests are relative to the current origin. |
| `VITE_OAUTH_CLIENT_ID` | OAuth 2.0 client ID. Defaults to `stalwart-webui`. |
| `VITE_ACCESS_TOKEN` | When set, skips the OAuth flow entirely and uses this token for all requests. Useful for local development and testing. | | `VITE_ACCESS_TOKEN` | When set, skips the OAuth flow entirely and uses this token for all requests. Useful for local development and testing. |
| `VITE_OAUTH_SCOPES` | Optional OAuth scopes. Omitted from the authorization request when empty. | | `VITE_OAUTH_SCOPES` | Optional OAuth scopes. Omitted from the authorization request when empty. |
### OAuth client ID
The OAuth 2.0 client ID is not a build-time setting. It is read at runtime from a meta tag in `index.html`:
```html
<meta name="oauth-client-id" content="" />
```
The server rewrites the `content` attribute when it serves the page, so a single build works for any deployment. When no
client ID is configured the attribute is left empty and the panel falls back to `stalwart-webui`.
### Bypassing OAuth for development ### Bypassing OAuth for development
Set `VITE_ACCESS_TOKEN` to a valid bearer token to skip the login page and go straight to the admin panel. You can obtain a token from the Stalwart server's token endpoint or use an API key: Set `VITE_ACCESS_TOKEN` to a valid bearer token to skip the login page and go straight to the admin panel. You can obtain a token from the Stalwart server's token endpoint or use an API key:
+1
View File
@@ -4,6 +4,7 @@
<head> <head>
<meta charset="UTF-8" /> <meta charset="UTF-8" />
<base href="/" /> <base href="/" />
<meta name="oauth-client-id" content="" />
<link rel="icon" type="image/x-icon" href="favicon.ico" /> <link rel="icon" type="image/x-icon" href="favicon.ico" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /> <meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>Portal</title> <title>Portal</title>
+1 -1
View File
@@ -1,7 +1,7 @@
{ {
"name": "stalwart-webui", "name": "stalwart-webui",
"private": true, "private": true,
"version": "1.0.8", "version": "1.0.9",
"description": "Stalwart WebUI", "description": "Stalwart WebUI",
"type": "module", "type": "module",
"scripts": { "scripts": {
+56
View File
@@ -0,0 +1,56 @@
/*
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*/
import { describe, it, expect, afterEach, vi } from 'vitest';
const originalHead = document.head.innerHTML;
async function loadWithMeta(meta: string) {
document.head.innerHTML = meta;
vi.resetModules();
const { getOAuthClientId } = await import('./oauthClientId');
return getOAuthClientId;
}
afterEach(() => {
document.head.innerHTML = originalHead;
vi.resetModules();
});
describe('getOAuthClientId', () => {
it('prefers the client id injected by the server', async () => {
const getOAuthClientId = await loadWithMeta('<meta name="oauth-client-id" content="pocket-id-client" />');
expect(getOAuthClientId()).toBe('pocket-id-client');
});
it('trims surrounding whitespace from the injected client id', async () => {
const getOAuthClientId = await loadWithMeta('<meta name="oauth-client-id" content=" pocket-id-client " />');
expect(getOAuthClientId()).toBe('pocket-id-client');
});
it('falls back to the built-in default when the placeholder is empty', async () => {
const getOAuthClientId = await loadWithMeta('<meta name="oauth-client-id" content="" />');
expect(getOAuthClientId()).toBe('stalwart-webui');
});
it('falls back to the built-in default when the placeholder is only whitespace', async () => {
const getOAuthClientId = await loadWithMeta('<meta name="oauth-client-id" content=" " />');
expect(getOAuthClientId()).toBe('stalwart-webui');
});
it('falls back to the built-in default when the placeholder is absent', async () => {
const getOAuthClientId = await loadWithMeta('');
expect(getOAuthClientId()).toBe('stalwart-webui');
});
it('reads the document only once', async () => {
const getOAuthClientId = await loadWithMeta('<meta name="oauth-client-id" content="pocket-id-client" />');
expect(getOAuthClientId()).toBe('pocket-id-client');
document.head.innerHTML = '<meta name="oauth-client-id" content="changed-later" />';
expect(getOAuthClientId()).toBe('pocket-id-client');
});
});
+17
View File
@@ -0,0 +1,17 @@
/*
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*/
const DEFAULT_CLIENT_ID = 'stalwart-webui';
let cached: string | undefined;
export function getOAuthClientId(): string {
if (cached !== undefined) return cached;
const injected = document.querySelector('meta[name="oauth-client-id"]')?.getAttribute('content')?.trim();
cached = injected ? injected : DEFAULT_CLIENT_ID;
return cached;
}
+2 -1
View File
@@ -6,6 +6,7 @@
import { useAuthStore } from '../stores/authStore'; import { useAuthStore } from '../stores/authStore';
import { getBasePath } from '@/lib/basePath'; import { getBasePath } from '@/lib/basePath';
import { getOAuthClientId } from '@/lib/oauthClientId';
export function getApiBaseUrl(): string { export function getApiBaseUrl(): string {
const envUrl = import.meta.env.VITE_API_BASE_URL as string | undefined; const envUrl = import.meta.env.VITE_API_BASE_URL as string | undefined;
@@ -45,7 +46,7 @@ export async function refreshAccessToken(): Promise<void> {
throw new Error('No refresh token or token endpoint available'); throw new Error('No refresh token or token endpoint available');
} }
const clientId = (import.meta.env.VITE_OAUTH_CLIENT_ID as string) || 'stalwart-webui'; const clientId = getOAuthClientId();
try { try {
const response = await fetch(tokenEndpoint, { const response = await fetch(tokenEndpoint, {
+4 -4
View File
@@ -6,9 +6,9 @@
import { getApiBaseUrl } from '@/services/api'; import { getApiBaseUrl } from '@/services/api';
import { getBasePath } from '@/lib/basePath'; import { getBasePath } from '@/lib/basePath';
import { getOAuthClientId } from '@/lib/oauthClientId';
import i18n from '@/i18n'; import i18n from '@/i18n';
const CLIENT_ID = (import.meta.env.VITE_OAUTH_CLIENT_ID as string) || 'stalwart-webui';
const SCOPES = import.meta.env.VITE_OAUTH_SCOPES as string | undefined; const SCOPES = import.meta.env.VITE_OAUTH_SCOPES as string | undefined;
const SESSION_PREFIX = 'stalwart-oauth-'; const SESSION_PREFIX = 'stalwart-oauth-';
@@ -97,7 +97,7 @@ export async function exchangeCode(
grant_type: 'authorization_code', grant_type: 'authorization_code',
code, code,
code_verifier: codeVerifier, code_verifier: codeVerifier,
client_id: CLIENT_ID, client_id: getOAuthClientId(),
redirect_uri: redirectUri, redirect_uri: redirectUri,
}); });
@@ -153,7 +153,7 @@ export async function startAuthFlow(username: string, returnUrl?: string | null)
const params = new URLSearchParams({ const params = new URLSearchParams({
response_type: 'code', response_type: 'code',
client_id: CLIENT_ID, client_id: getOAuthClientId(),
redirect_uri: getRedirectUri(), redirect_uri: getRedirectUri(),
code_challenge: codeChallenge, code_challenge: codeChallenge,
code_challenge_method: codeChallengeMethod, code_challenge_method: codeChallengeMethod,
@@ -206,7 +206,7 @@ export function getPostLogoutRedirectUri(): string {
export function buildEndSessionUrl(endSessionEndpoint: string, postLogoutRedirectUri: string): string { export function buildEndSessionUrl(endSessionEndpoint: string, postLogoutRedirectUri: string): string {
const params = new URLSearchParams({ const params = new URLSearchParams({
client_id: CLIENT_ID, client_id: getOAuthClientId(),
post_logout_redirect_uri: postLogoutRedirectUri, post_logout_redirect_uri: postLogoutRedirectUri,
}); });
const sep = endSessionEndpoint.includes('?') ? '&' : '?'; const sep = endSessionEndpoint.includes('?') ? '&' : '?';
-1
View File
@@ -8,7 +8,6 @@
interface ImportMetaEnv { interface ImportMetaEnv {
readonly VITE_API_BASE_URL: string; readonly VITE_API_BASE_URL: string;
readonly VITE_OAUTH_CLIENT_ID: string;
readonly VITE_ACCESS_TOKEN: string; readonly VITE_ACCESS_TOKEN: string;
readonly VITE_OAUTH_SCOPES: string; readonly VITE_OAUTH_SCOPES: string;
readonly VITE_DEBUG_JMAP?: string; readonly VITE_DEBUG_JMAP?: string;