chore: update config example

This commit is contained in:
Rorical 2024-12-22 23:04:56 +08:00
parent 8f43c94693
commit f356d08ec9
2 changed files with 11 additions and 3 deletions

View file

@ -364,10 +364,17 @@ unix_socket_permission: "0770"
# allowed_users: # allowed_users:
# - alice@example.com # - alice@example.com
# #
# # Optional: Enable PKCE (Proof Key for Code Exchange) support for enhanced security # # Optional: PKCE (Proof Key for Code Exchange) configuration
# # and prevent CSRF attacks. # # PKCE adds an additional layer of security to the OAuth 2.0 authorization code flow
# # by preventing authorization code interception attacks
# # See https://datatracker.ietf.org/doc/html/rfc7636 # # See https://datatracker.ietf.org/doc/html/rfc7636
# enable_pkce: false # pkce:
# # Enable or disable PKCE support (default: false)
# enabled: false
# # PKCE method to use:
# # - plain: Use plain code verifier
# # - S256: Use SHA256 hashed code verifier (default, recommended)
# method: S256
# #
# # Map legacy users from pre-0.24.0 versions of headscale to the new OIDC users # # Map legacy users from pre-0.24.0 versions of headscale to the new OIDC users
# # by taking the username from the legacy user and matching it with the username # # by taking the username from the legacy user and matching it with the username

View file

@ -48,6 +48,7 @@ oidc:
# Optional: PKCE (Proof Key for Code Exchange) configuration # Optional: PKCE (Proof Key for Code Exchange) configuration
# PKCE adds an additional layer of security to the OAuth 2.0 authorization code flow # PKCE adds an additional layer of security to the OAuth 2.0 authorization code flow
# by preventing authorization code interception attacks # by preventing authorization code interception attacks
# See https://datatracker.ietf.org/doc/html/rfc7636
pkce: pkce:
# Enable or disable PKCE support (default: false) # Enable or disable PKCE support (default: false)
enabled: false enabled: false