reactor(opaque): normalize to OXICLOUD_AUTH_OPAQUE_* variables
This commit is contained in:
+8
-10
@@ -188,15 +188,13 @@ DATABASE_URL=postgres://postgres:postgres@localhost:5432/oxicloud
|
||||
# Parallelism lanes (default: 2)
|
||||
#OXICLOUD_HASH_PARALLELISM=2
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# OPAQUE aPAKE (zero-knowledge password login, RFC 9807)
|
||||
# -----------------------------------------------------------------------------
|
||||
# --- OPAQUE aPAKE (zero-knowledge password login, RFC 9807) ------------------
|
||||
# OPAQUE replaces `POST /api/auth/login` with a zero-knowledge exchange:
|
||||
# the passphrase never leaves the client, not on registration and not on
|
||||
# login. This is the substrate for later E2EE work.
|
||||
#
|
||||
# Phase 0 (this build) ships the primitives only — endpoints are inert
|
||||
# until `OXICLOUD_OPAQUE_MODE` is set. Leave everything commented for a
|
||||
# until `OXICLOUD_AUTH_OPAQUE_MODE` is set. Leave everything commented for a
|
||||
# no-op install; OIDC-only and magic-link-only deployments never need to
|
||||
# touch OPAQUE at all (see the effective-mode downgrade below).
|
||||
|
||||
@@ -208,12 +206,12 @@ DATABASE_URL=postgres://postgres:postgres@localhost:5432/oxicloud
|
||||
# is disabled via OXICLOUD_AUTH_METHODS (OPAQUE has nothing to shadow) —
|
||||
# an audit-channel log line explains why. So enabling this without
|
||||
# password in OXICLOUD_AUTH_METHODS is a no-op, not a boot error.
|
||||
#OXICLOUD_OPAQUE_MODE=off
|
||||
#OXICLOUD_AUTH_OPAQUE_MODE=off
|
||||
|
||||
# Persistent OPAQUE server keypair (base64-encoded ServerSetup blob).
|
||||
# Generated ONCE per deployment; rotating this invalidates every user's
|
||||
# registration (they'd all be forced to re-register on next login). Only
|
||||
# required when `OXICLOUD_OPAQUE_MODE != off` AND password auth is
|
||||
# required when `OXICLOUD_AUTH_OPAQUE_MODE != off` AND password auth is
|
||||
# enabled — otherwise the value is ignored.
|
||||
#
|
||||
# Generate on first-time enable:
|
||||
@@ -225,7 +223,7 @@ DATABASE_URL=postgres://postgres:postgres@localhost:5432/oxicloud
|
||||
# pipelines capture cleanly). Paste the printed line into your env or
|
||||
# secrets manager. NEVER regenerate — treat it like your JWT secret;
|
||||
# losing it forces every user to reset their passphrase.
|
||||
#OXICLOUD_OPAQUE_SERVER_SETUP=
|
||||
#OXICLOUD_AUTH_OPAQUE_SERVER_SETUP=
|
||||
|
||||
# Client-side Argon2id key-stretching parameters (RFC 9807 KSF).
|
||||
# These run on the USER'S DEVICE during OPAQUE login/registration —
|
||||
@@ -238,11 +236,11 @@ DATABASE_URL=postgres://postgres:postgres@localhost:5432/oxicloud
|
||||
# the user's next password change.
|
||||
#
|
||||
# Memory cost in KiB (default: 262144 = 256 MiB)
|
||||
#OXICLOUD_OPAQUE_KSF_MEMORY_KIB=262144
|
||||
#OXICLOUD_AUTH_OPAQUE_KSF_MEMORY_KIB=262144
|
||||
# Iterations (default: 3)
|
||||
#OXICLOUD_OPAQUE_KSF_ITERATIONS=3
|
||||
#OXICLOUD_AUTH_OPAQUE_KSF_ITERATIONS=3
|
||||
# Parallelism lanes (default: 4)
|
||||
#OXICLOUD_OPAQUE_KSF_PARALLELISM=4
|
||||
#OXICLOUD_AUTH_OPAQUE_KSF_PARALLELISM=4
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# RATE LIMITING & ACCOUNT LOCKOUT
|
||||
|
||||
Reference in New Issue
Block a user