diff --git a/installer.sh b/installer.sh index 509cc1b..135acb7 100644 --- a/installer.sh +++ b/installer.sh @@ -339,6 +339,7 @@ PDS_CRAWLERS=${PDS_CRAWLERS} LOG_ENABLED=true PDS_RATE_LIMITS_ENABLED=true PDS_INVITE_REQUIRED=true +# PDS_OIDC_ISSUER_URL=https://atlogin.net PDS_CONFIG # diff --git a/sample.env b/sample.env index 0d23484..ba45eef 100644 --- a/sample.env +++ b/sample.env @@ -14,3 +14,4 @@ PDS_CRAWLERS=https://bsky.network LOG_ENABLED=true PDS_EMAIL_SMTP_URL= PDS_EMAIL_FROM_ADDRESS= +# PDS_OIDC_ISSUER_URL=https://atlogin.net diff --git a/service/index.js b/service/index.js index 4f83837..6b3d861 100644 --- a/service/index.js +++ b/service/index.js @@ -16,9 +16,32 @@ const main = async () => { const pds = await PDS.create(cfg, secrets); await pds.start(); httpLogger.info("pds has started"); + pds.app.get("/tls-check", (req, res) => { checkHandleRoute(pds, req, res); }); + + pds.app.get("/.well-known/webfinger", (req, res) => { + const resource = req.query.resource; + if (!resource) { + return res.status(400).json({ error: "missing resource parameter" }); + } + + const issuerUrl = process.env.PDS_OIDC_ISSUER_URL; + if (!issuerUrl) { + return res.status(404).json({ error: "webfinger not configured" }); + } + + res.setHeader("Content-Type", "application/jrd+json"); + res.json({ + subject: resource, + links: [{ + rel: "http://openid.net/specs/connect/1.0/issuer", + href: issuerUrl + }] + }); + }); + // Graceful shutdown (see also https://aws.amazon.com/blogs/containers/graceful-shutdowns-with-ecs/) process.on("SIGTERM", async () => { httpLogger.info("pds is stopping");