fix: use app password auth for background sync in Login Flow mode

Login Flow v2 is a deployment-wide mode where all users authenticate
with app passwords (not OAuth refresh tokens). Set use_basic_auth=True
when enable_login_flow is true so the background sync user manager
queries the app_passwords table and scanners use app password
authentication for Nextcloud API calls.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Chris Coutinho
2026-03-30 00:55:31 +02:00
co-authored by Claude Opus 4.6
parent 474cfe5e98
commit c21776948d
2 changed files with 4 additions and 12 deletions
+3 -3
View File
@@ -1807,9 +1807,9 @@ def get_app(transport: str = "streamable-http", enabled_apps: list[str] | None =
break
# Determine authentication mode for background sync
# Multi-user BasicAuth: use app passwords via Astrolabe (NOT OAuth)
# OAuth mode: use OAuth refresh tokens (NOT app passwords)
use_basic_auth = not oauth_enabled
# Login Flow v2 and multi-user BasicAuth: use app passwords
# OAuth mode (without Login Flow): use OAuth refresh tokens
use_basic_auth = not oauth_enabled or settings.enable_login_flow
# Start background tasks using anyio TaskGroup
async with anyio.create_task_group() as tg:
+1 -9
View File
@@ -489,21 +489,13 @@ async def user_manager_task(
try:
# Get current provisioned users based on mode
if use_basic_auth:
# BasicAuth mode: query app_passwords table
# BasicAuth / Login Flow v2 mode: query app_passwords table
provisioned_users = set(
await refresh_token_storage.get_all_app_password_user_ids()
)
else:
# OAuth mode: query refresh_tokens table
provisioned_users = set(await refresh_token_storage.get_all_user_ids())
# Login Flow mode: also check app_passwords table
# (users provisioned via Login Flow v2 have app passwords,
# not refresh tokens)
if settings.enable_login_flow:
app_pw_users = set(
await refresh_token_storage.get_all_app_password_user_ids()
)
provisioned_users |= app_pw_users
active_users = set(user_states.keys())
# Start scanners for new users