Files
shared-memory/.env.example
T
shadowdaoandClaude Opus 5 60cfb19772 fix: advertise the audience scope so tokens actually carry aud
The OAuth path to /api/mcp has never worked end to end. Every access token
arrived without an `aud` claim and jwt.ts rejected it with
"claim invalid: aud" (401), even though the handshake, consent and PKCE all
succeeded. Only the CLI HMAC path worked, because cli-token.ts sets the
audience itself — which is why this went unnoticed.

Cause: Authentik evaluates a scope mapping only when the client REQUESTS
that scope by name. An MCP client learns which scopes to request from
`scopes_supported` in our RFC 9728 protected-resource metadata, and we only
advertised openid/profile/email. So the `aud-shared-memory` mapping was
attached to the provider but never evaluated.

Advertise the audience scope in that metadata. Name is derived as
`aud-<OIDC_AUDIENCE>` to match the README convention, overridable with the
new optional OIDC_AUDIENCE_SCOPE for deployments that named it differently.

Also documents that Claude Code's RFC 8707 `resource` parameter is ignored
by Authentik 2026.5, so it cannot be relied on for audience binding.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-27 05:58:56 -07:00

91 lines
4.4 KiB
Bash

# =============================================================================
# shared-memory — example environment file
# Copy to `.env` and fill in real values. Never commit `.env`.
# =============================================================================
# -----------------------------------------------------------------------------
# Public URL the app is reached at.
# Used for OIDC redirect URIs, MCP discovery metadata, and Auth.js callbacks.
# -----------------------------------------------------------------------------
PUBLIC_URL=https://memory.example.com
# -----------------------------------------------------------------------------
# Deployment mode
# -----------------------------------------------------------------------------
# By default the app exposes a plain HTTP port to the host for use behind an
# external reverse proxy (HAProxy, nginx, Traefik, Cloudflare Tunnel, etc.).
APP_PORT=3000
# Bind interface for the exposed port. Use 127.0.0.1 to only accept traffic
# from a proxy on the same host. Default 0.0.0.0 accepts from anywhere.
APP_BIND=0.0.0.0
# The two settings below are ONLY consumed by the optional `caddy` service,
# which is started with: `docker compose --profile tls up -d`.
# Leave them as-is if you terminate TLS upstream (HAProxy, etc.).
APP_HOSTNAME=memory.example.com
ACME_EMAIL=you@example.com
# -----------------------------------------------------------------------------
# Authentik OIDC
# Create two Applications in Authentik (one for the Web UI, one for the MCP
# resource server). See README.md for exact provider settings.
# -----------------------------------------------------------------------------
OIDC_ISSUER=https://auth.example.com/application/o/shared-memory/
OIDC_CLIENT_ID_WEB=replace-me
OIDC_CLIENT_SECRET_WEB=replace-me
OIDC_CLIENT_ID_MCP=replace-me
OIDC_AUDIENCE=shared-memory
# Scope whose IdP mapping emits `aud: <OIDC_AUDIENCE>`. Advertised in
# /.well-known/oauth-protected-resource so MCP clients request it — without
# that, Authentik never evaluates the mapping and every token 401s with
# "claim invalid: aud". Defaults to aud-<OIDC_AUDIENCE>; set only if you
# named the scope mapping something else.
#OIDC_AUDIENCE_SCOPE=aud-shared-memory
# -----------------------------------------------------------------------------
# Database (Postgres 16 + pgvector — pgvector/pgvector:pg16 image)
# -----------------------------------------------------------------------------
POSTGRES_USER=memory
POSTGRES_PASSWORD=replace-me-with-a-strong-password
POSTGRES_DB=memory
# Built automatically by docker-compose from the values above. Override only
# if you point at an external Postgres.
# DATABASE_URL=postgres://memory:...@db:5432/memory
# When using docker-compose.external-db.yml, set DATABASE_URL explicitly.
# Example for AWS RDS Postgres with SSL:
# DATABASE_URL=postgres://memory:STRONG_PASSWORD@your-rds.region.rds.amazonaws.com:5432/memory?sslmode=require
# -----------------------------------------------------------------------------
# Embedder sidecar. Default points at the in-compose service.
# -----------------------------------------------------------------------------
EMBEDDER_URL=http://embedder:8080
EMBEDDING_MODEL=Xenova/bge-small-en-v1.5
EMBEDDING_DIM=384
# -----------------------------------------------------------------------------
# NextAuth session signing — generate with: openssl rand -base64 32
# -----------------------------------------------------------------------------
NEXTAUTH_SECRET=replace-me-with-32-bytes-of-random
# -----------------------------------------------------------------------------
# CLI token signing key. Used to mint HMAC-signed JWTs from /connect for
# pasting into MCP clients (Claude Code etc.). Rotate to invalidate all
# outstanding CLI tokens at once. Generate with: openssl rand -base64 32
# -----------------------------------------------------------------------------
CLI_TOKEN_SECRET=replace-me-with-32-bytes-of-random
# Lifetime (in days) of newly minted CLI tokens. Positive integer; unset or
# invalid values fall back to 90. Only affects tokens minted after this is set —
# already-issued tokens keep their original expiry.
# CLI_TOKEN_TTL_DAYS=90
# -----------------------------------------------------------------------------
# App
# -----------------------------------------------------------------------------
LOG_LEVEL=info
# Optional: pin to a specific built image (e.g. for a registry-pushed build).
# IMAGE_REF=registry.example.com/shared-memory-web:0.1.0