Repository navigation
Is OAuth2 supported in Homer11? #730
|
Hey! I've been using Homer7 for quite a while and have been looking at upgrading to Homer11. It seems like in Homer7 the Identity provider would redirect to Is OAuth2 fully supported, or is it currently a stub / on the roadmap? |
Replies: 7 comments 7 replies
|
I'm seeing the same thing here. Deploying a new Homer 11 instance with Authentik as the IdP. The login proceeds to authenticate with the IdP, redirects to the homer 11 callback with token and then HTTP 401. I've enabled debug logging but I do not see any logs indicating a problem with authentication in homer. Any advice? Docker instance variables: Client browser: HTTP GET 302 https://homer.url.local/api/v4/auth/oauth2/authentik/callback?code=!redacted!&state= Authentik log: { |
|
Lets us check it ASAP! |
|
So. Thanks you for reports: there are two separate issues showed up in this thread. First, after OAuth the UI lands on callback_url with a short-lived token in the query string. That value is not a JWT. The UI must call POST /api/v4/auth/oauth2/token with {"token":"..."} and use data.token as Authorization: Bearer .... Putting the query token directly in Authorization causes 401 on /me and dashboards. Second, the coordinator only enables OAuth when coordinator.oauth2_provider is set up for the authorization code flow: client_id, auth_url, token_url, redirect_url, profile_url, and either client_secret (if use_pkce is false) or use_pkce true for a public client. A single pre-built url field is no longer enough. Use examples/homer-coordinator-oauth2-code-flow.sample.json and docs/AUTH_LDAP_AND_OAUTH.md as references. Docker-style overrides use names like HOMER_COORDINATOR_OAUTH2_PROVIDER_CLIENT_ID, ..._AUTH_URL, ..._TOKEN_URL, and so on. The redirect URI registered at the IdP must match redirect_url exactly (same path and provider name as in /api/v4/auth/oauth2//callback). OAuth state and one-time tokens are in memory, so multiple coordinator instances behind a load balancer need sticky sessions or a shared store. Upgrade to a build that includes both the UI token exchange and the server-side code flow, then align IdP and env with the docs above. https://github.com/sipcapture/homer/releases/tag/11.0.219 Thank you again and have a nice evening! |
|
Hi @adubovikov, Thank you for the quick update. I can confirm that 11.0.219 and adding the following env vars for the docker deployment is working with Authentik. Now I just need to figure out how to deal with the admin_groups and env vars (Our admin group has a space in the name 'VoIP Admin'). HOMER_COORDINATOR_OAUTH2_PROVIDER_CLIENT_ID: "homer-ui" Best Regards! |
|
Thanks adubovikov. 2026-05-18T17:46:17Z DBG oauth2 admin group check provider=authentik group_claim=groups claim_present=false parsed_groups=[] admin_groups="[VoIP Admin]" admin_match=false My IdP response from the Authentik admin portal but as you can see above the log indicates the group_claim is not found.
|
|
I think I figured it out. I had to add 'profile' to the oauth2 scopes. HOMER_COORDINATOR_OAUTH2_PROVIDER_SCOPES: "openid email profile" 2026-05-18T18:13:21Z DBG oauth2 admin group check provider=authentik group_claim=groups claim_present=true parsed_groups="VoIP Admin SIPCapture Users]" admin_groups="[VoIP Admin]" admin_match=true Thanks for your help! |
|
@josh-hook please let us know if the path fixed your issue as well. |
So. Thanks you for reports:
there are two separate issues showed up in this thread.
First, after OAuth the UI lands on callback_url with a short-lived token in the query string. That value is not a JWT. The UI must call POST /api/v4/auth/oauth2/token with {"token":"..."} and use data.token as Authorization: Bearer .... Putting the query token directly in Authorization causes 401 on /me and dashboards.
Second, the coordinator only enables OAuth when coordinator.oauth2_provider is set up for the authorization code flow: client_id, auth_url, token_url, redirect_url, profile_url, and either client_secret (if use_pkce is false) or use_pkce true for a public client. A single pre-built url field…