reactor(opaque): normalize to OXICLOUD_AUTH_OPAQUE_* variables

This commit is contained in:
Edouard Vanbelle
2026-08-04 07:31:22 +02:00
parent 6a5b8980ae
commit 6965855388
15 changed files with 73 additions and 75 deletions
+8 -10
View File
@@ -188,15 +188,13 @@ DATABASE_URL=postgres://postgres:postgres@localhost:5432/oxicloud
# Parallelism lanes (default: 2)
#OXICLOUD_HASH_PARALLELISM=2
# -----------------------------------------------------------------------------
# OPAQUE aPAKE (zero-knowledge password login, RFC 9807)
# -----------------------------------------------------------------------------
# --- OPAQUE aPAKE (zero-knowledge password login, RFC 9807) ------------------
# OPAQUE replaces `POST /api/auth/login` with a zero-knowledge exchange:
# the passphrase never leaves the client, not on registration and not on
# login. This is the substrate for later E2EE work.
#
# Phase 0 (this build) ships the primitives only — endpoints are inert
# until `OXICLOUD_OPAQUE_MODE` is set. Leave everything commented for a
# until `OXICLOUD_AUTH_OPAQUE_MODE` is set. Leave everything commented for a
# no-op install; OIDC-only and magic-link-only deployments never need to
# touch OPAQUE at all (see the effective-mode downgrade below).
@@ -208,12 +206,12 @@ DATABASE_URL=postgres://postgres:postgres@localhost:5432/oxicloud
# is disabled via OXICLOUD_AUTH_METHODS (OPAQUE has nothing to shadow) —
# an audit-channel log line explains why. So enabling this without
# password in OXICLOUD_AUTH_METHODS is a no-op, not a boot error.
#OXICLOUD_OPAQUE_MODE=off
#OXICLOUD_AUTH_OPAQUE_MODE=off
# Persistent OPAQUE server keypair (base64-encoded ServerSetup blob).
# Generated ONCE per deployment; rotating this invalidates every user's
# registration (they'd all be forced to re-register on next login). Only
# required when `OXICLOUD_OPAQUE_MODE != off` AND password auth is
# required when `OXICLOUD_AUTH_OPAQUE_MODE != off` AND password auth is
# enabled — otherwise the value is ignored.
#
# Generate on first-time enable:
@@ -225,7 +223,7 @@ DATABASE_URL=postgres://postgres:postgres@localhost:5432/oxicloud
# pipelines capture cleanly). Paste the printed line into your env or
# secrets manager. NEVER regenerate — treat it like your JWT secret;
# losing it forces every user to reset their passphrase.
#OXICLOUD_OPAQUE_SERVER_SETUP=
#OXICLOUD_AUTH_OPAQUE_SERVER_SETUP=
# Client-side Argon2id key-stretching parameters (RFC 9807 KSF).
# These run on the USER'S DEVICE during OPAQUE login/registration —
@@ -238,11 +236,11 @@ DATABASE_URL=postgres://postgres:postgres@localhost:5432/oxicloud
# the user's next password change.
#
# Memory cost in KiB (default: 262144 = 256 MiB)
#OXICLOUD_OPAQUE_KSF_MEMORY_KIB=262144
#OXICLOUD_AUTH_OPAQUE_KSF_MEMORY_KIB=262144
# Iterations (default: 3)
#OXICLOUD_OPAQUE_KSF_ITERATIONS=3
#OXICLOUD_AUTH_OPAQUE_KSF_ITERATIONS=3
# Parallelism lanes (default: 4)
#OXICLOUD_OPAQUE_KSF_PARALLELISM=4
#OXICLOUD_AUTH_OPAQUE_KSF_PARALLELISM=4
# -----------------------------------------------------------------------------
# RATE LIMITING & ACCOUNT LOCKOUT