Round-1 review follow-ups: - Troubleshooting "Access forbidden": note that existing users must re-authorize once after switching to a static client (stored sessions were issued to the now-deleted DCR client). - Default IdP setup: explain that the `/mcp` resource identifier works because `_has_mcp_audience` accepts both the bare server URL and the `/mcp` form. - env.sample.oauth-multi-user: use angle-bracket placeholders (`<your-client-id>`) to match the template convention and fail loudly if copied verbatim. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
84 lines
3.3 KiB
Plaintext
84 lines
3.3 KiB
Plaintext
# ============================================
|
|
# LOGIN FLOW v2 MULTI-USER QUICK START (Recommended)
|
|
# ============================================
|
|
# Multi-user deployment with OAuth/OIDC authentication (ADR-022).
|
|
# Use for: Multi-user production deployments, enhanced security.
|
|
# The MCP server authenticates clients via OIDC and holds per-user
|
|
# Nextcloud app passwords (encrypted) obtained via Login Flow v2.
|
|
#
|
|
# See docs/login-flow-v2.md for the full guide.
|
|
# Copy this file to .env and configure
|
|
|
|
# ===== REQUIRED SETTINGS =====
|
|
# Your Nextcloud instance URL (without trailing slash)
|
|
NEXTCLOUD_HOST=https://nextcloud.example.com
|
|
|
|
# ===== REQUIRED: LEAVE USERNAME/PASSWORD EMPTY =====
|
|
# OAuth mode activates when these are NOT set
|
|
NEXTCLOUD_USERNAME=
|
|
NEXTCLOUD_PASSWORD=
|
|
|
|
# ===== REQUIRED: DEPLOYMENT MODE =====
|
|
MCP_DEPLOYMENT_MODE=login_flow
|
|
|
|
# ===== STRONGLY RECOMMENDED: STATIC OIDC CLIENT =====
|
|
# Register a static client for the MCP server in your IdP and set these.
|
|
# With Nextcloud's built-in `oidc` app you MUST do this: the DCR fallback
|
|
# registers an ephemeral client that the app deletes after ~1h, which breaks
|
|
# auth permanently ("Access forbidden" on reconnect — see issue #907).
|
|
# Create one under Administration settings -> OpenID Connect provider.
|
|
NEXTCLOUD_OIDC_CLIENT_ID=<your-client-id>
|
|
NEXTCLOUD_OIDC_CLIENT_SECRET=<your-client-secret>
|
|
|
|
# MCP Server URL (for OAuth redirects)
|
|
NEXTCLOUD_MCP_SERVER_URL=http://localhost:8000
|
|
|
|
# ===== OPTIONAL: SEMANTIC SEARCH (Recommended) =====
|
|
# AI-powered semantic search with automatic background operation setup
|
|
#
|
|
# When you enable semantic search in multi-user mode:
|
|
# 1. ENABLE_SEMANTIC_SEARCH automatically enables background operations
|
|
# 2. Server requests refresh tokens for offline indexing
|
|
# 3. Tokens are stored encrypted in TOKEN_STORAGE_DB
|
|
# 4. No need to set ENABLE_BACKGROUND_OPERATIONS separately!
|
|
#
|
|
ENABLE_SEMANTIC_SEARCH=true
|
|
|
|
# Vector Database (required for semantic search)
|
|
QDRANT_URL=http://qdrant:6333
|
|
# OR for in-memory mode:
|
|
#QDRANT_LOCATION=:memory:
|
|
|
|
# Embedding Provider (required for semantic search)
|
|
# Option 1: Ollama (recommended for local deployment)
|
|
OLLAMA_BASE_URL=http://ollama:11434
|
|
OLLAMA_EMBEDDING_MODEL=nomic-embed-text
|
|
|
|
# Option 2: Amazon Bedrock (for AWS deployments)
|
|
#AWS_REGION=us-east-1
|
|
#BEDROCK_EMBEDDING_MODEL=amazon.titan-embed-text-v2:0
|
|
|
|
# Token Storage (required for background operations - auto-enabled by semantic search)
|
|
# Generate encryption key: python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
|
|
TOKEN_ENCRYPTION_KEY=your-encryption-key-here
|
|
TOKEN_STORAGE_DB=/app/data/tokens.db
|
|
|
|
# ===== OPTIONAL: DOCUMENT PROCESSING =====
|
|
# Extract text from PDFs, images, DOCX for semantic search
|
|
#ENABLE_DOCUMENT_PROCESSING=true
|
|
#ENABLE_UNSTRUCTURED=true
|
|
#UNSTRUCTURED_API_URL=http://unstructured:8000
|
|
|
|
# ===== SUMMARY OF AUTO-ENABLEMENT =====
|
|
# With ENABLE_SEMANTIC_SEARCH=true in OAuth mode:
|
|
# ✅ Background operations enabled automatically
|
|
# ✅ Refresh token storage enabled automatically
|
|
# ✅ Static OIDC client credentials required (see above)
|
|
# ✅ Encryption key required for token storage
|
|
#
|
|
# You only need to set ENABLE_SEMANTIC_SEARCH and provide the required
|
|
# infrastructure (static OIDC client, Qdrant, Ollama, encryption key).
|
|
# The rest is automatic!
|
|
|
|
# For more advanced configuration, see env.sample
|