diff --git a/README.md b/README.md index d20f835..ce44391 100644 --- a/README.md +++ b/README.md @@ -37,14 +37,25 @@ Any app that supports OpenID Connect can use ATAuth. No custom integration neede ```bash git clone https://gitea.cloudforest-basilisk.ts.net/Arcnode.xyz/atauth.git -cd atauth +cd atauth/gateway cp .env.example .env -echo "ADMIN_TOKEN=$(openssl rand -hex 32)" >> .env +``` + +Edit `.env` and fill in the required secrets (generate with `openssl rand -hex 32`): + +```env +ADMIN_TOKEN= +OIDC_KEY_SECRET= +MFA_ENCRYPTION_KEY= # openssl rand -hex 32 +``` + +Then start: +```bash docker compose up -d ``` -Then open the admin dashboard at `http://localhost:3100/admin/login` and use the setup wizard to register your first app. +Open the admin dashboard at `https://your-domain/admin/login` and use the setup wizard to register your first app. ## Supported Apps @@ -120,11 +131,15 @@ With a self-hosted PDS, ATAuth becomes a fully independent auth system: ## Security +- No hardcoded secrets -- all sensitive config validated at startup - Client secrets stored as SHA-256 hashes +- One-time flash tokens for secret display (never in URLs) - PKCE support (configurable per-client) - Constant-time comparison for all secret verification +- HTML escaping on all server-rendered pages - HMAC-signed CSRF tokens on all dashboard forms - Rate limiting on auth endpoints +- CSP with per-request nonces for inline scripts - WAF-compatible (Cloudflare Managed Ruleset + OWASP) ## Documentation diff --git a/docs/HOMELAB.md b/docs/HOMELAB.md index 3991330..f13bc0b 100644 --- a/docs/HOMELAB.md +++ b/docs/HOMELAB.md @@ -12,15 +12,24 @@ ATAuth provides OIDC-based authentication for your homelab using AT Protocol ide ```bash git clone https://gitea.cloudforest-basilisk.ts.net/Arcnode.xyz/atauth.git -cd atauth +cd atauth/gateway cp .env.example .env +``` + +Edit `.env` with your configuration. At minimum, set these required secrets: + +```bash +# Generate and paste each value +openssl rand -hex 32 # for ADMIN_TOKEN +openssl rand -hex 32 # for OIDC_KEY_SECRET +openssl rand -hex 32 # for MFA_ENCRYPTION_KEY (produces 64 hex chars) +``` -# Generate admin token -echo "ADMIN_TOKEN=$(openssl rand -hex 32)" >> .env +Also update `OAUTH_CLIENT_ID`, `OAUTH_REDIRECT_URI`, `OIDC_ISSUER`, and `WEBAUTHN_*` to match your domain. -# Set your public URL -# Edit .env: OAUTH_CLIENT_ID and OAUTH_REDIRECT_URI +Then start: +```bash docker compose up -d ``` @@ -178,8 +187,18 @@ docker run --rm -v atauth_atauth-data:/data -v $(pwd):/backup alpine \ ## Updating +Using the pre-built image from GHCR: + +```bash +docker pull ghcr.io/cache8063/atauth-gateway:latest +docker compose up -d +``` + +Or if building locally: + ```bash -docker compose pull +git pull +docker compose build docker compose up -d ```