fix: use app password auth for background sync in Login Flow mode
Login Flow v2 is a deployment-wide mode where all users authenticate with app passwords (not OAuth refresh tokens). Set use_basic_auth=True when enable_login_flow is true so the background sync user manager queries the app_passwords table and scanners use app password authentication for Nextcloud API calls. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
474cfe5e98
commit
c21776948d
@@ -1807,9 +1807,9 @@ def get_app(transport: str = "streamable-http", enabled_apps: list[str] | None =
|
|||||||
break
|
break
|
||||||
|
|
||||||
# Determine authentication mode for background sync
|
# Determine authentication mode for background sync
|
||||||
# Multi-user BasicAuth: use app passwords via Astrolabe (NOT OAuth)
|
# Login Flow v2 and multi-user BasicAuth: use app passwords
|
||||||
# OAuth mode: use OAuth refresh tokens (NOT app passwords)
|
# OAuth mode (without Login Flow): use OAuth refresh tokens
|
||||||
use_basic_auth = not oauth_enabled
|
use_basic_auth = not oauth_enabled or settings.enable_login_flow
|
||||||
|
|
||||||
# Start background tasks using anyio TaskGroup
|
# Start background tasks using anyio TaskGroup
|
||||||
async with anyio.create_task_group() as tg:
|
async with anyio.create_task_group() as tg:
|
||||||
|
|||||||
@@ -489,21 +489,13 @@ async def user_manager_task(
|
|||||||
try:
|
try:
|
||||||
# Get current provisioned users based on mode
|
# Get current provisioned users based on mode
|
||||||
if use_basic_auth:
|
if use_basic_auth:
|
||||||
# BasicAuth mode: query app_passwords table
|
# BasicAuth / Login Flow v2 mode: query app_passwords table
|
||||||
provisioned_users = set(
|
provisioned_users = set(
|
||||||
await refresh_token_storage.get_all_app_password_user_ids()
|
await refresh_token_storage.get_all_app_password_user_ids()
|
||||||
)
|
)
|
||||||
else:
|
else:
|
||||||
# OAuth mode: query refresh_tokens table
|
# OAuth mode: query refresh_tokens table
|
||||||
provisioned_users = set(await refresh_token_storage.get_all_user_ids())
|
provisioned_users = set(await refresh_token_storage.get_all_user_ids())
|
||||||
# Login Flow mode: also check app_passwords table
|
|
||||||
# (users provisioned via Login Flow v2 have app passwords,
|
|
||||||
# not refresh tokens)
|
|
||||||
if settings.enable_login_flow:
|
|
||||||
app_pw_users = set(
|
|
||||||
await refresh_token_storage.get_all_app_password_user_ids()
|
|
||||||
)
|
|
||||||
provisioned_users |= app_pw_users
|
|
||||||
active_users = set(user_states.keys())
|
active_users = set(user_states.keys())
|
||||||
|
|
||||||
# Start scanners for new users
|
# Start scanners for new users
|
||||||
|
|||||||
Reference in New Issue
Block a user