diff --git a/docker-compose.prod.yml b/docker-compose.prod.yml index 6ed57dd..61286b5 100644 --- a/docker-compose.prod.yml +++ b/docker-compose.prod.yml @@ -213,7 +213,7 @@ services: # Bump: `docker buildx imagetools inspect ghcr.io/bluesky-social/pds:`. # Same depends_on caveat as postgres above: a changed pin is applied by # the next `up -d caddy` unless --no-deps is used. - image: ghcr.io/bluesky-social/pds:0.4.193@sha256:50e60af25fa7b580ddae8fc18ae97b1d7cdeb1a3068a3d345f9161cc7796417b + image: ghcr.io/bluesky-social/pds:0.4.5027@sha256:d95725b24dbe53af9d91dc69750556931ebed6c396f2cfa42b221434db642f12 container_name: coves-prod-pds restart: unless-stopped ports: -- 2.51.2 From 8a79c1525649d75d4a9bb0ffc509f98ea2d19ce4 Mon Sep 17 00:00:00 2001 From: Bretton Date: Thu, 27 Aug 2026 00:01:41 -0700 Subject: [PATCH 2/2] chore(oauth): remove legacy public client-metadata.json The AppView has registered as a confidential client at /oauth-client-metadata.json (private_key_jwt, served by HandleClientMetadata) since Jan 2026; the static public document at /client-metadata.json (token_endpoint_auth_method: none) was last used by two sessions in Nov 2025 and is referenced by no code or client. Drop the file, its Caddy route, and the unused OAUTH_CLIENT_ID env passthrough so the only advertised OAuth client is the confidential one. Co-Authored-By: Claude Fable 5 --- Caddyfile | 6 ------ docker-compose.prod.yml | 3 +-- static/client-metadata.json | 18 ------------------ 3 files changed, 1 insertion(+), 26 deletions(-) delete mode 100644 static/client-metadata.json diff --git a/Caddyfile b/Caddyfile index 05081ac..ffd1726 100644 --- a/Caddyfile +++ b/Caddyfile @@ -107,12 +107,6 @@ coves.social { file_server } - # Serve OAuth client metadata - handle /client-metadata.json { - root * /srv - file_server - } - # /img/* belongs to the media hostname, and only to the media hostname. # # The AppView registers the image-proxy route on its router with no Host diff --git a/docker-compose.prod.yml b/docker-compose.prod.yml index 61286b5..2bbb38f 100644 --- a/docker-compose.prod.yml +++ b/docker-compose.prod.yml @@ -96,7 +96,6 @@ services: SKIP_DID_WEB_VERIFICATION: "false" # OAuth (for community account provisioning) - OAUTH_CLIENT_ID: ${OAUTH_CLIENT_ID} OAUTH_REDIRECT_URI: ${OAUTH_REDIRECT_URI} OAUTH_SEAL_SECRET: ${OAUTH_SEAL_SECRET} @@ -322,7 +321,7 @@ services: - ./Caddyfile:/etc/caddy/Caddyfile:ro - caddy-data:/data - caddy-config:/config - # Static files (.well-known, client-metadata.json, oauth callback) + # Static files (.well-known DID docs, images) - ./static:/srv:ro networks: - coves-internal diff --git a/static/client-metadata.json b/static/client-metadata.json deleted file mode 100644 index 00ea85d..0000000 --- a/static/client-metadata.json +++ /dev/null @@ -1,18 +0,0 @@ -{ - "client_id": "https://coves.social/client-metadata.json", - "client_name": "Coves", - "client_uri": "https://coves.social", - "logo_uri": "https://coves.social/logo.png", - "tos_uri": "https://coves.social/terms", - "policy_uri": "https://coves.social/privacy", - "redirect_uris": [ - "https://coves.social/oauth/callback", - "social.coves:/oauth/callback" - ], - "scope": "atproto", - "grant_types": ["authorization_code", "refresh_token"], - "response_types": ["code"], - "application_type": "native", - "token_endpoint_auth_method": "none", - "dpop_bound_access_tokens": true -}