Compare commits

..
20 Commits
Author SHA1 Message Date
Max Deichmann e21102664e chore: release v2.95.2 2025-02-15 13:29:57 +01:00
Max DeichmannandGitHub d31b0eaddc security: upgrade dompurify v2 (#5570)
security: upgrade dompurify
2025-02-15 12:26:51 +00:00
Max Deichmann f53ad4de5c chore: release v2.95.1
Codespell / Check for spelling errors (push) Waiting to run
CI/CD / lint (push) Waiting to run
CI/CD / test-docker-build (push) Waiting to run
CI/CD / tests-web-sync (node20, pg12) (push) Waiting to run
CI/CD / tests-web-sync (node20, pg15) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / e2e-tests (push) Waiting to run
CI/CD / e2e-server-tests (push) Waiting to run
CI/CD / all-ci-passed (push) Blocked by required conditions
CI/CD / push-docker-image (push) Blocked by required conditions
2025-02-11 14:19:25 +01:00
Max DeichmannandGitHub 053d7d668d security: upgrade sentry 8.52.0 (#5477)
fix
2025-02-11 14:18:38 +01:00
Max DeichmannandGitHub 21e3ed2b39 security: upgrade clickhouse migration package (#5478)
push
2025-02-11 14:18:26 +01:00
Max DeichmannandGitHub 16ca4e9293 security: upgrade json path (#5475) 2025-02-11 13:44:51 +01:00
Marc KlingenandGitHub 75f82be88d ci(v2): run codespell also on v2 branch and prs (#5224) (#5225) 2025-01-27 13:25:31 +01:00
Marc Klingen 22f6a02b08 chore: release v2.95.0
CI/CD / lint (push) Waiting to run
CI/CD / test-docker-build (push) Waiting to run
CI/CD / tests-web-sync (node20, pg12) (push) Waiting to run
CI/CD / tests-web-sync (node20, pg15) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / e2e-tests (push) Waiting to run
CI/CD / e2e-server-tests (push) Waiting to run
CI/CD / all-ci-passed (push) Blocked by required conditions
CI/CD / push-docker-image (push) Blocked by required conditions
2025-01-27 13:16:16 +01:00
Marc KlingenandGitHub 11aa1dbbb1 feat(v2-auth): make checks and auth method configurable across SSO providers (#5203) (#5219) 2025-01-27 13:15:33 +01:00
steffen911 d961d85a28 chore: release v2.94.0
CI/CD / lint (push) Waiting to run
CI/CD / test-docker-build (push) Waiting to run
CI/CD / tests-web-sync (node20, pg12) (push) Waiting to run
CI/CD / tests-web-sync (node20, pg15) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / e2e-tests (push) Waiting to run
CI/CD / e2e-server-tests (push) Waiting to run
CI/CD / all-ci-passed (push) Blocked by required conditions
CI/CD / push-docker-image (push) Blocked by required conditions
2025-01-24 16:35:20 +01:00
Steffen SchmitzandGitHub d0c1ad5144 feat: add proxy support for oauth flows (#5198) (#5201)
(cherry picked from commit c442c4290e)
2025-01-24 16:34:53 +01:00
Marc Klingen 0d30b2fe83 chore: release v2.93.9
CI/CD / lint (push) Waiting to run
CI/CD / test-docker-build (push) Waiting to run
CI/CD / tests-web-sync (node20, pg12) (push) Waiting to run
CI/CD / tests-web-sync (node20, pg15) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / e2e-tests (push) Waiting to run
CI/CD / e2e-server-tests (push) Waiting to run
CI/CD / all-ci-passed (push) Blocked by required conditions
CI/CD / push-docker-image (push) Blocked by required conditions
2025-01-24 14:12:59 +01:00
Marc KlingenandGitHub f33bae6683 feat(auth-v2): Add AUTH_CUSTOM_ID_TOKEN environment variable (#5193) (#5196) 2025-01-24 14:12:00 +01:00
Baptiste Mille-MathiasandGitHub eaa0df125b feat: add support for DATABASE_ARGS config (cherry-pick) (#5152) 2025-01-24 13:50:17 +01:00
Max Deichmann b0e01b7127 chore: release v2.93.8
CI/CD / lint (push) Waiting to run
CI/CD / test-docker-build (push) Waiting to run
CI/CD / tests-web-sync (node20, pg12) (push) Waiting to run
CI/CD / tests-web-sync (node20, pg15) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / e2e-tests (push) Waiting to run
CI/CD / e2e-server-tests (push) Waiting to run
CI/CD / all-ci-passed (push) Blocked by required conditions
CI/CD / push-docker-image (push) Blocked by required conditions
2025-01-06 10:54:29 +01:00
Max DeichmannandGitHub 2a421e7406 security: upgrade next (#4891)
push
2025-01-06 10:45:23 +01:00
Marc Klingen 23150b68db chore: release v2.93.7
CI/CD / lint (push) Waiting to run
CI/CD / test-docker-build (push) Waiting to run
CI/CD / tests-web-sync (node20, pg12) (push) Waiting to run
CI/CD / tests-web-sync (node20, pg15) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / e2e-tests (push) Waiting to run
CI/CD / e2e-server-tests (push) Waiting to run
CI/CD / all-ci-passed (push) Blocked by required conditions
CI/CD / push-docker-image (push) Blocked by required conditions
2024-12-19 00:57:59 +01:00
Ildar IapparovandMarc Klingen e5c46010a4 feat(auth): add AUTH_IGNORE_ACCOUNT_FIELDS to sanitize IDP fields before creating an account (#4728)
* feat: Field sanitization before creating an Account

* add comments

---------

Co-authored-by: Marc Klingen <git@marcklingen.com>
2024-12-19 00:57:07 +01:00
Marc Klingen b2bf68d7a4 chore: release v2.93.6
CI/CD / lint (push) Waiting to run
CI/CD / test-docker-build (push) Waiting to run
CI/CD / tests-web-sync (node20, pg12) (push) Waiting to run
CI/CD / tests-web-sync (node20, pg15) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-web-async (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-web-async (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode) (push) Waiting to run
CI/CD / tests-worker (node20, pg12, mode-azure) (push) Waiting to run
CI/CD / tests-worker (node20, pg15, mode-azure) (push) Waiting to run
CI/CD / e2e-tests (push) Waiting to run
CI/CD / e2e-server-tests (push) Waiting to run
CI/CD / all-ci-passed (push) Blocked by required conditions
CI/CD / push-docker-image (push) Blocked by required conditions
2024-12-13 02:57:59 +01:00
Marc Klingen 31cec4f5c9 feat: in HF Spaces, prompt opening in new tab when running in iframe (#4713) 2024-12-13 02:45:32 +01:00
26 changed files with 1251 additions and 621 deletions
+3 -1
View File
@@ -55,6 +55,7 @@ OTEL_SERVICE_NAME="langfuse"
# Auth, optional configuration
# AUTH_DOMAINS_WITH_SSO_ENFORCEMENT=domain1.com,domain2.com
# AUTH_IGNORE_ACCOUNT_FIELDS=foo,bar
# AUTH_DISABLE_USERNAME_PASSWORD=true
# AUTH_DISABLE_SIGNUP=true
# AUTH_SESSION_MAX_AGE=43200 # 30 days in minutes (default)
@@ -101,6 +102,7 @@ OTEL_SERVICE_NAME="langfuse"
# AUTH_CUSTOM_NAME=
# AUTH_CUSTOM_SCOPE="openid email profile" # optional
# AUTH_CUSTOM_ALLOW_ACCOUNT_LINKING=false
# AUTH_CUSTOM_ID_TOKEN=false # optional, default is true
# Transactional email, optional
# Defines the email address to use as the from address.
@@ -253,4 +255,4 @@ OTEL_SERVICE_NAME="langfuse"
# LANGFUSE_ASYNC_INGESTION_PROCESSING="true"
# QUEUE_CONSUMER_LEGACY_INGESTION_QUEUE_IS_ENABLED="true"
## END Langfuse V3 Ingestion
## END Langfuse V3 Ingestion
+7 -2
View File
@@ -3,9 +3,14 @@ name: Codespell
on:
push:
branches: [main]
branches:
- "main"
tags:
- "v*"
pull_request:
branches: [main]
branches:
- "**"
merge_group:
permissions:
contents: read
+4 -4
View File
@@ -82,7 +82,7 @@ jobs:
- uses: actions/checkout@v4
- name: Install golang-migrate for Clickhouse migrations
run: |
curl -L https://github.com/golang-migrate/migrate/releases/download/v4.16.2/migrate.linux-amd64.tar.gz | tar xvz
curl -L https://github.com/golang-migrate/migrate/releases/download/v4.18.2/migrate.linux-amd64.tar.gz | tar xvz
sudo mv migrate /usr/bin/migrate
which migrate
- uses: pnpm/action-setup@v3
@@ -151,7 +151,7 @@ jobs:
- uses: actions/checkout@v4
- name: Install golang-migrate for Clickhouse migrations
run: |
curl -L https://github.com/golang-migrate/migrate/releases/download/v4.16.2/migrate.linux-amd64.tar.gz | tar xvz
curl -L https://github.com/golang-migrate/migrate/releases/download/v4.18.2/migrate.linux-amd64.tar.gz | tar xvz
sudo mv migrate /usr/bin/migrate
which migrate
- uses: pnpm/action-setup@v3
@@ -237,7 +237,7 @@ jobs:
pnpm install
- name: Install golang-migrate for Clickhouse migrations
run: |
curl -L https://github.com/golang-migrate/migrate/releases/download/v4.16.2/migrate.linux-amd64.tar.gz | tar xvz
curl -L https://github.com/golang-migrate/migrate/releases/download/v4.18.2/migrate.linux-amd64.tar.gz | tar xvz
sudo mv migrate /usr/bin/migrate
which migrate
- name: Load default env
@@ -330,7 +330,7 @@ jobs:
pnpm install
- name: Install golang-migrate for Clickhouse migrations
run: |
curl -L https://github.com/golang-migrate/migrate/releases/download/v4.16.2/migrate.linux-amd64.tar.gz | tar xvz
curl -L https://github.com/golang-migrate/migrate/releases/download/v4.18.2/migrate.linux-amd64.tar.gz | tar xvz
sudo mv migrate /usr/bin/migrate
which migrate
- name: Load default env
+3 -2
View File
@@ -27,7 +27,8 @@
"@langfuse/shared": "workspace:*",
"@opentelemetry/api": ">=1.0.0 <1.10.0",
"axios": "^1.7.7",
"next": "^14.2.15",
"https-proxy-agent": "^7.0.6",
"next": "^14.2.21",
"next-auth": "^4.24.11",
"zod": "^3.23.8"
},
@@ -47,7 +48,7 @@
},
"pnpm": {
"overrides": {
"jsonpath-plus": "10.0.7"
"jsonpath-plus": "10.2.0"
}
}
}
+7 -2
View File
@@ -1,6 +1,6 @@
{
"name": "langfuse",
"version": "2.93.5",
"version": "2.95.2",
"author": "engineering@langfuse.com",
"license": "MIT",
"private": true,
@@ -83,7 +83,12 @@
},
"pnpm": {
"overrides": {
"jsonpath-plus": "10.0.7"
"jsonpath-plus": "10.2.0",
"nanoid": "^3.3.8",
"katex": "^0.16.21"
},
"patchedDependencies": {
"next-auth@4.24.11": "patches/next-auth@4.24.11.patch"
}
},
"packageManager": "pnpm@9.5.0"
+1
View File
@@ -76,6 +76,7 @@
"dd-trace": "^5.23.1",
"decimal.js": "^10.4.3",
"exponential-backoff": "^3.1.1",
"https-proxy-agent": "^7.0.6",
"ioredis": "^5.4.1",
"kysely": "^0.27.4",
"langchain": "^0.3.6",
@@ -17,7 +17,6 @@ export function CustomSSOProvider<P extends CustomSSOUser>(
wellKnown: `${options.issuer}/.well-known/openid-configuration`,
authorization: { params: { scope: "openid email profile" } }, // overridden by options.authorization to be able to set custom scopes, deep merged with this default
checks: ["pkce", "state"],
idToken: true,
profile(profile) {
return {
id: profile.sub,
+26
View File
@@ -0,0 +1,26 @@
diff --git a/core/lib/oauth/client.js b/core/lib/oauth/client.js
index 52c51eb6ff422dc0899ccec31baf3fa39e42eeae..bc50c35bb617d0e86b68ca42f64d44b475ba4abb 100644
--- a/core/lib/oauth/client.js
+++ b/core/lib/oauth/client.js
@@ -1,5 +1,7 @@
"use strict";
+var HttpsProxyAgent = require('https-proxy-agent').HttpsProxyAgent;
+
Object.defineProperty(exports, "__esModule", {
value: true
});
@@ -7,7 +9,12 @@ exports.openidClient = openidClient;
var _openidClient = require("openid-client");
async function openidClient(options) {
const provider = options.provider;
- if (provider.httpOptions) _openidClient.custom.setHttpOptionsDefaults(provider.httpOptions);
+ let httpOptions = {};
+ if (provider.httpOptions) httpOptions = { ...provider.httpOptions };
+ if (process.env.AUTH_HTTPS_PROXY || process.env.AUTH_HTTP_PROXY) {
+ httpOptions.agent = new HttpsProxyAgent(process.env.AUTH_HTTPS_PROXY || process.env.AUTH_HTTP_PROXY);
+ }
+ _openidClient.custom.setHttpOptionsDefaults(httpOptions);
let issuer;
if (provider.wellKnown) {
issuer = await _openidClient.Issuer.discover(provider.wellKnown);
+903 -576
View File
File diff suppressed because it is too large Load Diff
+1 -1
View File
@@ -109,7 +109,7 @@ RUN adduser --system --uid 1001 nextjs
RUN npm install -g --no-package-lock --no-save prisma@5.22.0
RUN MIGRATE_TARGET_ARCH=$(echo ${TARGETPLATFORM:-linux/amd64} | sed 's/\//-/g') && \
wget -q -O- https://github.com/golang-migrate/migrate/releases/download/v4.18.0/migrate.$MIGRATE_TARGET_ARCH.tar.gz | tar xvz && \
wget -q -O- https://github.com/golang-migrate/migrate/releases/download/v4.18.2/migrate.$MIGRATE_TARGET_ARCH.tar.gz | tar xvz && \
mv migrate /usr/bin/migrate
COPY --from=builder --chown=nextjs:nodejs /app/web/next.config.mjs .
+6 -1
View File
@@ -12,11 +12,16 @@ if [ -z "$DATABASE_URL" ]; then
echo "Error: Required database environment variables are not set. Provide a postgres url for DATABASE_URL."
exit 1
fi
if [ -n "$DATABASE_ARGS" ]; then
# Append ARGS to DATABASE_URL
DATABASE_URL="${DATABASE_URL}?$DATABASE_ARGS"
export DATABASE_URL
fi
fi
# Set DIRECT_URL to the value of DATABASE_URL if it is not set, required for migrations
if [ -z "$DIRECT_URL" ]; then
export DIRECT_URL=$DATABASE_URL
export DIRECT_URL="${DATABASE_URL}"
fi
# Always execute the postgres migration, except when disabled.
+5 -4
View File
@@ -1,6 +1,6 @@
{
"name": "web",
"version": "2.93.5",
"version": "2.95.2",
"private": true,
"license": "MIT",
"engines": {
@@ -83,7 +83,7 @@
"@remixicon/react": "^4.2.0",
"@repo/eslint-config": "workspace:*",
"@repo/typescript-config": "workspace:*",
"@sentry/nextjs": "^8.39.0",
"@sentry/nextjs": "^8.52.0",
"@t3-oss/env-nextjs": "^0.11.1",
"@tailwindcss/container-queries": "^0.1.1",
"@tanstack/react-query": "^4.36.1",
@@ -107,8 +107,9 @@
"date-fns": "^3.3.1",
"dd-trace": "^5.23.1",
"decimal.js": "^10.4.3",
"dompurify": "^3.1.5",
"dompurify": "^3.2.4",
"graphql": "^16.9.0",
"https-proxy-agent": "^7.0.6",
"ioredis": "^5.4.1",
"ip-address": "^9.0.5",
"js-tiktoken": "^1.0.15",
@@ -116,7 +117,7 @@
"langchain": "^0.3.6",
"lodash": "^4.17.21",
"lucide-react": "^0.447.0",
"next": "^14.2.15",
"next": "^14.2.21",
"next-auth": "^4.24.11",
"next-query-params": "^5.0.1",
"next-themes": "^0.3.0",
File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 34 KiB

+1
View File
@@ -57,6 +57,7 @@ const unauthenticatedPaths: string[] = [
"/auth/sign-in",
"/auth/sign-up",
"/auth/error",
"/auth/hf-spaces",
];
// auth or unauthed
const publishablePaths: string[] = [
+1 -1
View File
@@ -1 +1 @@
export const VERSION = "v2.93.5";
export const VERSION = "v2.95.2";
@@ -69,7 +69,7 @@ import { showSuccessToast } from "@/src/features/notifications/showSuccessToast"
const formSchema = z.object({
scoreName: z.string(),
target: z.string(),
filter: z.array(singleFilter).nullable(), // re-using the filter type from the tables
filter: z.array(singleFilter).nullable(), // reusing the filter type from the tables
mapping: z.array(wipVariableMapping),
sampling: z.coerce.number().gt(0).lte(1),
delay: z.coerce.number().optional().default(10),
+2 -2
View File
@@ -35,7 +35,7 @@ const APIEvaluatorSchema = z.object({
evalTemplateId: z.string(),
scoreName: z.string(),
targetObject: z.string(),
filter: z.array(singleFilter).nullable(), // re-using the filter type from the tables
filter: z.array(singleFilter).nullable(), // reusing the filter type from the tables
variableMapping: z.array(variableMapping),
sampling: z.instanceof(Prisma.Decimal),
delay: z.number(),
@@ -91,7 +91,7 @@ const CreateEvalJobSchema = z.object({
evalTemplateId: z.string(),
scoreName: z.string().min(1),
target: z.string(),
filter: z.array(singleFilter).nullable(), // re-using the filter type from the tables
filter: z.array(singleFilter).nullable(), // reusing the filter type from the tables
mapping: z.array(variableMapping),
sampling: z.number().gt(0).lte(1),
delay: z.number().gte(0).default(DEFAULT_TRACE_JOB_DELAY), // 10 seconds default
+15 -12
View File
@@ -29,17 +29,17 @@ export const GithubProviderSchema = base.extend({
});
export const GithubEnterpriseProviderSchema = base.extend({
authProvider: z.literal("github-enterprise"),
authConfig: z
.object({
clientId: z.string(),
clientSecret: z.string(),
enterprise: z.object({
baseUrl: z.string().url(),
}),
allowDangerousEmailAccountLinking: z.boolean().optional().default(false),
})
.nullish(),
authProvider: z.literal("github-enterprise"),
authConfig: z
.object({
clientId: z.string(),
clientSecret: z.string(),
enterprise: z.object({
baseUrl: z.string().url(),
}),
allowDangerousEmailAccountLinking: z.boolean().optional().default(false),
})
.nullish(),
});
export const GitlabProviderSchema = base.extend({
@@ -123,6 +123,7 @@ export const CustomProviderSchema = base.extend({
clientSecret: z.string(),
issuer: z.string(),
scope: z.string().nullish(),
idToken: z.boolean().optional().default(true),
allowDangerousEmailAccountLinking: z.boolean().optional().default(false),
})
.nullish(),
@@ -130,7 +131,9 @@ export const CustomProviderSchema = base.extend({
export type GoogleProviderSchema = z.infer<typeof GoogleProviderSchema>;
export type GithubProviderSchema = z.infer<typeof GithubProviderSchema>;
export type GithubEnterpriseProviderSchema = z.infer<typeof GithubEnterpriseProviderSchema>;
export type GithubEnterpriseProviderSchema = z.infer<
typeof GithubEnterpriseProviderSchema
>;
export type GitlabProviderSchema = z.infer<typeof GitlabProviderSchema>;
export type Auth0ProviderSchema = z.infer<typeof Auth0ProviderSchema>;
export type OktaProviderSchema = z.infer<typeof OktaProviderSchema>;
+78 -4
View File
@@ -1,6 +1,26 @@
import { z } from "zod";
import { createEnv } from "@t3-oss/env-nextjs";
const zAuthMethod = z
.enum([
"client_secret_basic",
"client_secret_post",
"client_secret_jwt",
"private_key_jwt",
"tls_client_auth",
"self_signed_tls_client_auth",
"none",
])
.optional()
.default("client_secret_basic");
const zAuthChecks = z
.string()
.optional()
.transform((s) => s?.split(",").map((s) => s.trim()))
.pipe(z.array(z.enum(["nonce", "none", "pkce", "state"])).optional());
export const env = createEnv({
/**
* Specify your server-side environment variables schema here. This way you can ensure the app
@@ -54,44 +74,68 @@ export const env = createEnv({
AUTH_GOOGLE_CLIENT_SECRET: z.string().optional(),
AUTH_GOOGLE_ALLOWED_DOMAINS: z.string().optional(),
AUTH_GOOGLE_ALLOW_ACCOUNT_LINKING: z.enum(["true", "false"]).optional(),
AUTH_GOOGLE_CLIENT_AUTH_METHOD: zAuthMethod,
AUTH_GOOGLE_CHECKS: zAuthChecks,
AUTH_GITHUB_CLIENT_ID: z.string().optional(),
AUTH_GITHUB_CLIENT_SECRET: z.string().optional(),
AUTH_GITHUB_ALLOW_ACCOUNT_LINKING: z.enum(["true", "false"]).optional(),
AUTH_GITHUB_CLIENT_AUTH_METHOD: zAuthMethod,
AUTH_GITHUB_CHECKS: zAuthChecks,
AUTH_GITHUB_ENTERPRISE_CLIENT_ID: z.string().optional(),
AUTH_GITHUB_ENTERPRISE_CLIENT_SECRET: z.string().optional(),
AUTH_GITHUB_ENTERPRISE_BASE_URL: z.string().optional(),
AUTH_GITHUB_ENTERPRISE_ALLOW_ACCOUNT_LINKING: z.enum(["true", "false"]).optional(),
AUTH_GITHUB_ENTERPRISE_ALLOW_ACCOUNT_LINKING: z
.enum(["true", "false"])
.optional(),
AUTH_GITHUB_ENTERPRISE_CLIENT_AUTH_METHOD: zAuthMethod,
AUTH_GITHUB_ENTERPRISE_CHECKS: zAuthChecks,
AUTH_GITLAB_CLIENT_ID: z.string().optional(),
AUTH_GITLAB_CLIENT_SECRET: z.string().optional(),
AUTH_GITLAB_ALLOW_ACCOUNT_LINKING: z.enum(["true", "false"]).optional(),
AUTH_GITLAB_ISSUER: z.string().optional(),
AUTH_GITLAB_CLIENT_AUTH_METHOD: zAuthMethod,
AUTH_GITLAB_CHECKS: zAuthChecks,
AUTH_AZURE_AD_CLIENT_ID: z.string().optional(),
AUTH_AZURE_AD_CLIENT_SECRET: z.string().optional(),
AUTH_AZURE_AD_TENANT_ID: z.string().optional(),
AUTH_AZURE_ALLOW_ACCOUNT_LINKING: z.enum(["true", "false"]).optional(),
AUTH_AZURE_CLIENT_AUTH_METHOD: zAuthMethod,
AUTH_AZURE_CHECKS: zAuthChecks,
AUTH_OKTA_CLIENT_ID: z.string().optional(),
AUTH_OKTA_CLIENT_SECRET: z.string().optional(),
AUTH_OKTA_ISSUER: z.string().optional(),
AUTH_OKTA_ALLOW_ACCOUNT_LINKING: z.enum(["true", "false"]).optional(),
AUTH_OKTA_CHECKS: zAuthChecks,
AUTH_OKTA_CLIENT_AUTH_METHOD: zAuthMethod,
AUTH_AUTH0_CLIENT_ID: z.string().optional(),
AUTH_AUTH0_CLIENT_SECRET: z.string().optional(),
AUTH_AUTH0_ISSUER: z.string().url().optional(),
AUTH_AUTH0_ALLOW_ACCOUNT_LINKING: z.enum(["true", "false"]).optional(),
AUTH_AUTH0_CLIENT_AUTH_METHOD: zAuthMethod,
AUTH_AUTH0_CHECKS: zAuthChecks,
AUTH_COGNITO_CLIENT_ID: z.string().optional(),
AUTH_COGNITO_CLIENT_SECRET: z.string().optional(),
AUTH_COGNITO_ISSUER: z.string().url().optional(),
AUTH_COGNITO_ALLOW_ACCOUNT_LINKING: z.enum(["true", "false"]).optional(),
AUTH_COGNITO_CLIENT_AUTH_METHOD: zAuthMethod,
AUTH_COGNITO_CHECKS: zAuthChecks,
AUTH_KEYCLOAK_CLIENT_ID: z.string().optional(),
AUTH_KEYCLOAK_CLIENT_SECRET: z.string().optional(),
AUTH_KEYCLOAK_ISSUER: z.string().optional(),
AUTH_KEYCLOAK_ALLOW_ACCOUNT_LINKING: z.enum(["true", "false"]).optional(),
AUTH_KEYCLOAK_CLIENT_AUTH_METHOD: zAuthMethod,
AUTH_KEYCLOAK_CHECKS: zAuthChecks,
AUTH_CUSTOM_CLIENT_ID: z.string().optional(),
AUTH_CUSTOM_CLIENT_SECRET: z.string().optional(),
AUTH_CUSTOM_ISSUER: z.string().url().optional(),
AUTH_CUSTOM_NAME: z.string().optional(),
AUTH_CUSTOM_SCOPE: z.string().optional(),
AUTH_CUSTOM_CLIENT_AUTH_METHOD: zAuthMethod,
AUTH_CUSTOM_CHECKS: zAuthChecks,
AUTH_CUSTOM_ALLOW_ACCOUNT_LINKING: z.enum(["true", "false"]).optional(),
AUTH_CUSTOM_ID_TOKEN: z.enum(["true", "false"]).optional(),
AUTH_DOMAINS_WITH_SSO_ENFORCEMENT: z.string().optional(),
AUTH_IGNORE_ACCOUNT_FIELDS: z.string().optional(),
AUTH_DISABLE_USERNAME_PASSWORD: z.enum(["true", "false"]).optional(),
AUTH_DISABLE_SIGNUP: z.enum(["true", "false"]).optional(),
AUTH_SESSION_MAX_AGE: z.coerce
@@ -103,6 +147,8 @@ export const env = createEnv({
)
.optional()
.default(30 * 24 * 60), // default to 30 days
AUTH_HTTP_PROXY: z.string().url().optional(),
AUTH_HTTPS_PROXY: z.string().url().optional(),
// EMAIL
EMAIL_FROM_ADDRESS: z.string().optional(),
SMTP_CONNECTION_URL: z.string().optional(),
@@ -295,57 +341,85 @@ export const env = createEnv({
AUTH_GOOGLE_ALLOWED_DOMAINS: process.env.AUTH_GOOGLE_ALLOWED_DOMAINS,
AUTH_GOOGLE_ALLOW_ACCOUNT_LINKING:
process.env.AUTH_GOOGLE_ALLOW_ACCOUNT_LINKING,
AUTH_GOOGLE_CLIENT_AUTH_METHOD: process.env.AUTH_GOOGLE_CLIENT_AUTH_METHOD,
AUTH_GOOGLE_CHECKS: process.env.AUTH_GOOGLE_CHECKS,
AUTH_GITHUB_CLIENT_ID: process.env.AUTH_GITHUB_CLIENT_ID,
AUTH_GITHUB_CLIENT_SECRET: process.env.AUTH_GITHUB_CLIENT_SECRET,
AUTH_GITHUB_ALLOW_ACCOUNT_LINKING:
process.env.AUTH_GITHUB_ALLOW_ACCOUNT_LINKING,
AUTH_GITHUB_ENTERPRISE_CLIENT_ID: process.env.AUTH_GITHUB_ENTERPRISE_CLIENT_ID,
AUTH_GITHUB_ENTERPRISE_CLIENT_SECRET: process.env.AUTH_GITHUB_ENTERPRISE_CLIENT_SECRET,
AUTH_GITHUB_ENTERPRISE_BASE_URL: process.env.AUTH_GITHUB_ENTERPRISE_BASE_URL,
AUTH_GITHUB_CLIENT_AUTH_METHOD: process.env.AUTH_GITHUB_CLIENT_AUTH_METHOD,
AUTH_GITHUB_CHECKS: process.env.AUTH_GITHUB_CHECKS,
AUTH_GITHUB_ENTERPRISE_CLIENT_ID:
process.env.AUTH_GITHUB_ENTERPRISE_CLIENT_ID,
AUTH_GITHUB_ENTERPRISE_CLIENT_SECRET:
process.env.AUTH_GITHUB_ENTERPRISE_CLIENT_SECRET,
AUTH_GITHUB_ENTERPRISE_BASE_URL:
process.env.AUTH_GITHUB_ENTERPRISE_BASE_URL,
AUTH_GITHUB_ENTERPRISE_ALLOW_ACCOUNT_LINKING:
process.env.AUTH_GITHUB_ENTERPRISE_ALLOW_ACCOUNT_LINKING,
AUTH_GITHUB_ENTERPRISE_CLIENT_AUTH_METHOD:
process.env.AUTH_GITHUB_ENTERPRISE_CLIENT_AUTH_METHOD,
AUTH_GITHUB_ENTERPRISE_CHECKS: process.env.AUTH_GITHUB_ENTERPRISE_CHECKS,
AUTH_GITLAB_ISSUER: process.env.AUTH_GITLAB_ISSUER,
AUTH_GITLAB_CLIENT_ID: process.env.AUTH_GITLAB_CLIENT_ID,
AUTH_GITLAB_CLIENT_SECRET: process.env.AUTH_GITLAB_CLIENT_SECRET,
AUTH_GITLAB_ALLOW_ACCOUNT_LINKING:
process.env.AUTH_GITLAB_ALLOW_ACCOUNT_LINKING,
AUTH_GITLAB_CLIENT_AUTH_METHOD: process.env.AUTH_GITLAB_CLIENT_AUTH_METHOD,
AUTH_GITLAB_CHECKS: process.env.AUTH_GITLAB_CHECKS,
AUTH_AZURE_AD_CLIENT_ID: process.env.AUTH_AZURE_AD_CLIENT_ID,
AUTH_AZURE_AD_CLIENT_SECRET: process.env.AUTH_AZURE_AD_CLIENT_SECRET,
AUTH_AZURE_AD_TENANT_ID: process.env.AUTH_AZURE_AD_TENANT_ID,
AUTH_AZURE_ALLOW_ACCOUNT_LINKING:
process.env.AUTH_AZURE_ALLOW_ACCOUNT_LINKING,
AUTH_AZURE_CLIENT_AUTH_METHOD: process.env.AUTH_AZURE_CLIENT_AUTH_METHOD,
AUTH_AZURE_CHECKS: process.env.AUTH_AZURE_CHECKS,
AUTH_OKTA_CLIENT_ID: process.env.AUTH_OKTA_CLIENT_ID,
AUTH_OKTA_CLIENT_SECRET: process.env.AUTH_OKTA_CLIENT_SECRET,
AUTH_OKTA_ISSUER: process.env.AUTH_OKTA_ISSUER,
AUTH_OKTA_ALLOW_ACCOUNT_LINKING:
process.env.AUTH_OKTA_ALLOW_ACCOUNT_LINKING,
AUTH_OKTA_CLIENT_AUTH_METHOD: process.env.AUTH_OKTA_CLIENT_AUTH_METHOD,
AUTH_OKTA_CHECKS: process.env.AUTH_OKTA_CHECKS,
AUTH_AUTH0_CLIENT_ID: process.env.AUTH_AUTH0_CLIENT_ID,
AUTH_AUTH0_CLIENT_SECRET: process.env.AUTH_AUTH0_CLIENT_SECRET,
AUTH_AUTH0_ISSUER: process.env.AUTH_AUTH0_ISSUER,
AUTH_AUTH0_ALLOW_ACCOUNT_LINKING:
process.env.AUTH_AUTH0_ALLOW_ACCOUNT_LINKING,
AUTH_AUTH0_CLIENT_AUTH_METHOD: process.env.AUTH_AUTH0_CLIENT_AUTH_METHOD,
AUTH_AUTH0_CHECKS: process.env.AUTH_AUTH0_CHECKS,
AUTH_COGNITO_CLIENT_ID: process.env.AUTH_COGNITO_CLIENT_ID,
AUTH_COGNITO_CLIENT_SECRET: process.env.AUTH_COGNITO_CLIENT_SECRET,
AUTH_COGNITO_ISSUER: process.env.AUTH_COGNITO_ISSUER,
AUTH_COGNITO_ALLOW_ACCOUNT_LINKING:
process.env.AUTH_COGNITO_ALLOW_ACCOUNT_LINKING,
AUTH_COGNITO_CLIENT_AUTH_METHOD: process.env.AUTH_COGNITO_CLIENT_AUTH_METHOD,
AUTH_COGNITO_CHECKS: process.env.AUTH_COGNITO_CHECKS,
AUTH_KEYCLOAK_CLIENT_ID: process.env.AUTH_KEYCLOAK_CLIENT_ID,
AUTH_KEYCLOAK_CLIENT_SECRET: process.env.AUTH_KEYCLOAK_CLIENT_SECRET,
AUTH_KEYCLOAK_ISSUER: process.env.AUTH_KEYCLOAK_ISSUER,
AUTH_KEYCLOAK_ALLOW_ACCOUNT_LINKING:
process.env.AUTH_KEYCLOAK_ALLOW_ACCOUNT_LINKING,
AUTH_KEYCLOAK_CLIENT_AUTH_METHOD: process.env.AUTH_KEYCLOAK_CLIENT_AUTH_METHOD,
AUTH_KEYCLOAK_CHECKS: process.env.AUTH_KEYCLOAK_CHECKS,
AUTH_CUSTOM_CLIENT_ID: process.env.AUTH_CUSTOM_CLIENT_ID,
AUTH_CUSTOM_CLIENT_SECRET: process.env.AUTH_CUSTOM_CLIENT_SECRET,
AUTH_CUSTOM_ISSUER: process.env.AUTH_CUSTOM_ISSUER,
AUTH_CUSTOM_NAME: process.env.AUTH_CUSTOM_NAME,
AUTH_CUSTOM_SCOPE: process.env.AUTH_CUSTOM_SCOPE,
AUTH_CUSTOM_CLIENT_AUTH_METHOD: process.env.AUTH_CUSTOM_CLIENT_AUTH_METHOD,
AUTH_CUSTOM_CHECKS: process.env.AUTH_CUSTOM_CHECKS,
AUTH_CUSTOM_ALLOW_ACCOUNT_LINKING:
process.env.AUTH_CUSTOM_ALLOW_ACCOUNT_LINKING,
AUTH_CUSTOM_ID_TOKEN: process.env.AUTH_CUSTOM_ID_TOKEN,
AUTH_IGNORE_ACCOUNT_FIELDS: process.env.AUTH_IGNORE_ACCOUNT_FIELDS,
AUTH_DOMAINS_WITH_SSO_ENFORCEMENT:
process.env.AUTH_DOMAINS_WITH_SSO_ENFORCEMENT,
AUTH_DISABLE_USERNAME_PASSWORD: process.env.AUTH_DISABLE_USERNAME_PASSWORD,
AUTH_DISABLE_SIGNUP: process.env.AUTH_DISABLE_SIGNUP,
AUTH_SESSION_MAX_AGE: process.env.AUTH_SESSION_MAX_AGE,
AUTH_HTTP_PROXY: process.env.AUTH_HTTP_PROXY,
AUTH_HTTPS_PROXY: process.env.AUTH_HTTPS_PROXY,
// Email
EMAIL_FROM_ADDRESS: process.env.EMAIL_FROM_ADDRESS,
SMTP_CONNECTION_URL: process.env.SMTP_CONNECTION_URL,
+71
View File
@@ -0,0 +1,71 @@
/**
* When running Langfuse in HuggingFace Spaces, the app needs to be opened in a new tab.
* Otherwise, the app will not be able to access the session cookie.
*/
import { Button } from "@/src/components/ui/button";
import { LangfuseIcon } from "@/src/components/LangfuseLogo";
import Head from "next/head";
import Link from "next/link";
import { type GetServerSideProps } from "next";
import { env } from "@/src/env.mjs";
import { PlusIcon } from "lucide-react";
import { CodeView } from "@/src/components/ui/CodeJsonViewer";
type PageProps = {
deploymentDomain: string;
};
export const getServerSideProps: GetServerSideProps<PageProps> = async () => {
// remove /api/auth from the URL as it needs to be added for custom base url
const deploymentDomain = env.NEXTAUTH_URL?.replace("/api/auth", "");
return {
props: {
deploymentDomain,
},
};
};
export default function HfSpaces({ deploymentDomain }: PageProps) {
return (
<>
<Head>
<title>Langfuse on Hugging Face</title>
</Head>
<div className="flex flex-1 flex-col py-6 sm:min-h-full sm:justify-center sm:px-6 sm:py-12 lg:px-8">
<div className="sm:mx-auto sm:w-full sm:max-w-md">
<div className="flex items-center justify-center gap-2">
<LangfuseIcon />
<PlusIcon size={12} className="ml-1" />
{/* eslint-disable-next-line @next/next/no-img-element */}
<img
src="/assets/huggingface-logo.svg"
alt="Hugging Face Logo"
width={36}
height={36}
/>
</div>
<h2 className="mt-4 text-center text-2xl font-bold leading-9 tracking-tight text-primary">
Langfuse on Hugging Face
</h2>
</div>
<div className="mt-14 bg-background px-6 py-10 shadow sm:mx-auto sm:w-full sm:max-w-[480px] sm:rounded-lg sm:px-10">
<div className="space-y-8">
<CodeView content={deploymentDomain} title="HF Space Host" />
<Button className="w-full" asChild>
<Link
href={deploymentDomain}
target="_blank"
rel="noopener noreferrer"
>
Open in new tab
</Link>
</Button>
</div>
</div>
</div>
</>
);
}
+38 -1
View File
@@ -60,6 +60,7 @@ export type PageProps = {
| false;
sso: boolean;
};
runningOnHuggingFaceSpaces: boolean;
signUpDisabled: boolean;
};
@@ -114,6 +115,10 @@ export const getServerSideProps: GetServerSideProps<PageProps> = async () => {
sso,
},
signUpDisabled: env.AUTH_DISABLE_SIGNUP === "true",
runningOnHuggingFaceSpaces: env.NEXTAUTH_URL?.replace(
"/api/auth",
"",
).endsWith(".hf.space"),
},
};
};
@@ -263,6 +268,33 @@ export function SSOButtons({
);
}
/**
* Redirect to HuggingFace Spaces auth page (/auth/hf-spaces) if running in an iframe on a HuggingFace host.
* The iframe detection needs to happen client-side since window/document objects are not available during SSR.
* @param runningOnHuggingFaceSpaces - whether the app is running on a HuggingFace spaces, needs to be checked server-side
*/
export function useHuggingFaceRedirect(runningOnHuggingFaceSpaces: boolean) {
const router = useRouter();
useEffect(() => {
const isInIframe = () => {
try {
return window.self !== window.top;
} catch (e) {
return true;
}
};
if (
runningOnHuggingFaceSpaces &&
typeof window !== "undefined" &&
isInIframe()
) {
void router.push("/auth/hf-spaces");
}
}, [router, runningOnHuggingFaceSpaces]);
}
const signInErrors = [
{
code: "OAuthAccountNotLinked",
@@ -271,8 +303,13 @@ const signInErrors = [
},
];
export default function SignIn({ authProviders, signUpDisabled }: PageProps) {
export default function SignIn({
authProviders,
signUpDisabled,
runningOnHuggingFaceSpaces,
}: PageProps) {
const router = useRouter();
useHuggingFaceRedirect(runningOnHuggingFaceSpaces);
// handle NextAuth error codes: https://next-auth.js.org/configuration/pages#sign-in-page
const nextAuthError =
+11 -2
View File
@@ -20,7 +20,11 @@ import { useState } from "react";
import { LangfuseIcon } from "@/src/components/LangfuseLogo";
import { CloudPrivacyNotice } from "@/src/features/auth/components/AuthCloudPrivacyNotice";
import { CloudRegionSwitch } from "@/src/features/auth/components/AuthCloudRegionSwitch";
import { SSOButtons, type PageProps } from "@/src/pages/auth/sign-in";
import {
SSOButtons,
useHuggingFaceRedirect,
type PageProps,
} from "@/src/pages/auth/sign-in";
import { PasswordInput } from "@/src/components/ui/password-input";
import { Divider } from "@tremor/react";
import { Turnstile } from "@marsidev/react-turnstile";
@@ -28,7 +32,12 @@ import { Turnstile } from "@marsidev/react-turnstile";
// Use the same getServerSideProps function as src/pages/auth/sign-in.tsx
export { getServerSideProps } from "@/src/pages/auth/sign-in";
export default function SignIn({ authProviders }: PageProps) {
export default function SignIn({
authProviders,
runningOnHuggingFaceSpaces,
}: PageProps) {
useHuggingFaceRedirect(runningOnHuggingFaceSpaces);
const [turnstileToken, setTurnstileToken] = useState<string>();
// Used to refresh turnstile as the token can only be used once
const [turnstileCData, setTurnstileCData] = useState<string>(
+51 -1
View File
@@ -175,11 +175,16 @@ if (
clientId: env.AUTH_CUSTOM_CLIENT_ID,
clientSecret: env.AUTH_CUSTOM_CLIENT_SECRET,
issuer: env.AUTH_CUSTOM_ISSUER,
idToken: env.AUTH_CUSTOM_ID_TOKEN !== "false", // defaults to true
allowDangerousEmailAccountLinking:
env.AUTH_CUSTOM_ALLOW_ACCOUNT_LINKING === "true",
authorization: {
params: { scope: env.AUTH_CUSTOM_SCOPE ?? "openid email profile" },
},
client: {
token_endpoint_auth_method: env.AUTH_CUSTOM_CLIENT_AUTH_METHOD,
},
checks: env.AUTH_CUSTOM_CHECKS,
}),
);
@@ -190,6 +195,10 @@ if (env.AUTH_GOOGLE_CLIENT_ID && env.AUTH_GOOGLE_CLIENT_SECRET)
clientSecret: env.AUTH_GOOGLE_CLIENT_SECRET,
allowDangerousEmailAccountLinking:
env.AUTH_GOOGLE_ALLOW_ACCOUNT_LINKING === "true",
client: {
token_endpoint_auth_method: env.AUTH_GOOGLE_CLIENT_AUTH_METHOD,
},
checks: env.AUTH_GOOGLE_CHECKS,
}),
);
@@ -205,6 +214,10 @@ if (
issuer: env.AUTH_OKTA_ISSUER,
allowDangerousEmailAccountLinking:
env.AUTH_OKTA_ALLOW_ACCOUNT_LINKING === "true",
client: {
token_endpoint_auth_method: env.AUTH_OKTA_CLIENT_AUTH_METHOD,
},
checks: env.AUTH_OKTA_CHECKS,
}),
);
@@ -220,6 +233,10 @@ if (
issuer: env.AUTH_AUTH0_ISSUER,
allowDangerousEmailAccountLinking:
env.AUTH_AUTH0_ALLOW_ACCOUNT_LINKING === "true",
client: {
token_endpoint_auth_method: env.AUTH_AUTH0_CLIENT_AUTH_METHOD,
},
checks: env.AUTH_AUTH0_CHECKS,
}),
);
@@ -230,6 +247,10 @@ if (env.AUTH_GITHUB_CLIENT_ID && env.AUTH_GITHUB_CLIENT_SECRET)
clientSecret: env.AUTH_GITHUB_CLIENT_SECRET,
allowDangerousEmailAccountLinking:
env.AUTH_GITHUB_ALLOW_ACCOUNT_LINKING === "true",
client: {
token_endpoint_auth_method: env.AUTH_GITHUB_CLIENT_AUTH_METHOD,
},
checks: env.AUTH_GITHUB_CHECKS,
}),
);
@@ -245,6 +266,11 @@ if (
enterprise: { baseUrl: env.AUTH_GITHUB_ENTERPRISE_BASE_URL },
allowDangerousEmailAccountLinking:
env.AUTH_GITHUB_ENTERPRISE_ALLOW_ACCOUNT_LINKING === "true",
client: {
token_endpoint_auth_method:
env.AUTH_GITHUB_ENTERPRISE_CLIENT_AUTH_METHOD,
},
checks: env.AUTH_GITHUB_ENTERPRISE_CHECKS,
}),
);
}
@@ -257,6 +283,10 @@ if (env.AUTH_GITLAB_CLIENT_ID && env.AUTH_GITLAB_CLIENT_SECRET)
allowDangerousEmailAccountLinking:
env.AUTH_GITLAB_ALLOW_ACCOUNT_LINKING === "true",
issuer: env.AUTH_GITLAB_ISSUER,
client: {
token_endpoint_auth_method: env.AUTH_GITLAB_CLIENT_AUTH_METHOD,
},
checks: env.AUTH_GITLAB_CHECKS,
}),
);
@@ -272,6 +302,10 @@ if (
tenantId: env.AUTH_AZURE_AD_TENANT_ID,
allowDangerousEmailAccountLinking:
env.AUTH_AZURE_ALLOW_ACCOUNT_LINKING === "true",
client: {
token_endpoint_auth_method: env.AUTH_AZURE_CLIENT_AUTH_METHOD,
},
checks: env.AUTH_AZURE_CHECKS,
}),
);
@@ -285,9 +319,12 @@ if (
clientId: env.AUTH_COGNITO_CLIENT_ID,
clientSecret: env.AUTH_COGNITO_CLIENT_SECRET,
issuer: env.AUTH_COGNITO_ISSUER,
checks: "nonce",
checks: env.AUTH_COGNITO_CHECKS ?? "nonce",
allowDangerousEmailAccountLinking:
env.AUTH_COGNITO_ALLOW_ACCOUNT_LINKING === "true",
client: {
token_endpoint_auth_method: env.AUTH_COGNITO_CLIENT_AUTH_METHOD,
},
}),
);
@@ -303,11 +340,16 @@ if (
issuer: env.AUTH_KEYCLOAK_ISSUER,
allowDangerousEmailAccountLinking:
env.AUTH_KEYCLOAK_ALLOW_ACCOUNT_LINKING === "true",
client: {
token_endpoint_auth_method: env.AUTH_KEYCLOAK_CLIENT_AUTH_METHOD,
},
checks: env.AUTH_KEYCLOAK_CHECKS,
}),
);
// Extend Prisma Adapter
const prismaAdapter = PrismaAdapter(prisma);
const ignoredAccountFields = env.AUTH_IGNORE_ACCOUNT_FIELDS?.split(",") ?? [];
const extendedPrismaAdapter: Adapter = {
...prismaAdapter,
async createUser(profile: Omit<AdapterUser, "id">) {
@@ -346,6 +388,14 @@ const extendedPrismaAdapter: Adapter = {
delete data["not-before-policy"];
}
// Optionally, remove fields returned by the provider that cause issues with the adapter
// Configure via AUTH_IGNORE_ACCOUNT_FIELDS
for (const ignoredField of ignoredAccountFields) {
if (ignoredField in data) {
delete data[ignoredField];
}
}
await prismaAdapter.linkAccount(data);
},
};
+5
View File
@@ -12,6 +12,11 @@ if [ -z "$DATABASE_URL" ]; then
echo "Error: Required database environment variables are not set. Provide a postgres url for DATABASE_URL."
exit 1
fi
if [ -n "$DATABASE_ARGS" ]; then
# Append ARGS to DATABASE_URL
DATABASE_URL="${DATABASE_URL}?$DATABASE_ARGS"
export DATABASE_URL
fi
fi
# Run the command passed to the docker image on start
+2 -2
View File
@@ -1,6 +1,6 @@
{
"name": "worker",
"version": "2.93.5",
"version": "2.95.2",
"description": "",
"license": "MIT",
"private": true,
@@ -82,7 +82,7 @@
},
"pnpm": {
"overrides": {
"jsonpath-plus": "10.0.7"
"jsonpath-plus": "10.2.0"
}
}
}
+1 -1
View File
@@ -1 +1 @@
export const VERSION = "v2.93.5";
export const VERSION = "v2.95.2";