ac2bdef96e
1. Identity model — email is the identity, three optional credential slots (username, password_hash, oidc_subject), the @-in-username ban that makes namespaces provably disjoint. 2. Login dispatcher — @-in-input decides the path. Single DB lookup. 3. Login paths — four ways in (username+password, email+password, email+magic-link, OIDC redirect) with their pre-conditions. 4. Magic-link eligibility ladder — the three-branch table with OIDC unconditional reject, password flag-gated, no-credential allowed. 5. Registration paths — four ways (/api/auth/register with full creds, email-only, grant-by-email invitation, OIDC JIT). 6. Anti-enumeration — per-endpoint table showing what each surface returns and why; explicit note that instance-wide policy stays visible. 7. Security trade-offs — mailbox-as-bypass (lenient vs strict), no native MFA, magic-link as bearer token, enumeration via timing. 8. Rate limits — the five caps from PR 12 + classic auth, with env knobs. 9. Audit events — table of 12 event names with reason keys; every entry verified grep-able in src/. 10. Migration path — what existing instances see when PR 16-20 land (forward-only, non-destructive). 11. Future direction — login_strategy — the seven-row matrix sketch as the explicit-policy north star. 12. Out of scope — TOTP/WebAuthn, external→internal promotion, session_kind, differentiated session TTL, OCM, email-verified gates (PR 23), device-bound tokens (PR 22), anti-enum timing parity, per-user opt-out, login_strategy implementation. 13. Related documents — cross-refs to magic-link-auth, ReBAC, share-integration, env-vars.
137 lines
4.6 KiB
TypeScript
137 lines
4.6 KiB
TypeScript
import { defineConfig } from "vitepress";
|
|
|
|
export default defineConfig({
|
|
title: "OxiCloud",
|
|
description: "Self-hosted cloud storage, calendar & contacts — blazingly fast",
|
|
|
|
base: "/OxiCloud/",
|
|
|
|
sitemap: {
|
|
hostname: "https://diocrafts.github.io/OxiCloud",
|
|
lastmodDateOnly: false,
|
|
},
|
|
|
|
// Internal planning notes (docs/plan/*) and AI hand-off prompts
|
|
// aren't user-facing docs and contain raw Rust/pseudocode whose
|
|
// generics (Option<String>, Vec<SubjectGroup>, …) trip Vue's
|
|
// template parser ("Element is missing end tag" because <String>,
|
|
// <SubjectGroup>, etc. look like unclosed HTML tags). Keep them
|
|
// in-tree for engineering reference but skip them at site-build time.
|
|
srcExclude: [
|
|
"plan/**",
|
|
"**/*.prompt",
|
|
],
|
|
|
|
markdown: {
|
|
image: {
|
|
lazyLoading: true,
|
|
},
|
|
},
|
|
|
|
lastUpdated: true,
|
|
|
|
ignoreDeadLinks: [
|
|
/^https?:\/\/localhost/,
|
|
],
|
|
|
|
locales: {
|
|
root: {
|
|
label: "English",
|
|
lang: "en",
|
|
},
|
|
},
|
|
|
|
head: [
|
|
["link", { rel: "icon", href: "/OxiCloud/logo.svg" }],
|
|
],
|
|
|
|
themeConfig: {
|
|
logo: "/logo.svg",
|
|
|
|
search: {
|
|
provider: "local",
|
|
},
|
|
|
|
editLink: {
|
|
pattern: "https://github.com/DioCrafts/OxiCloud/tree/main/docs/:path",
|
|
text: "Edit this page on GitHub",
|
|
},
|
|
|
|
nav: [
|
|
{ text: "Home", link: "/" },
|
|
{ text: "Guide", link: "/guide/" },
|
|
{ text: "Configuration", link: "/config/" },
|
|
{ text: "FAQ", link: "/faq" },
|
|
],
|
|
|
|
sidebar: {
|
|
"/": [
|
|
{
|
|
text: "Introduction",
|
|
items: [
|
|
{ text: "What is OxiCloud?", link: "/guide/" },
|
|
{ text: "Quick Start", link: "/guide/installation" },
|
|
],
|
|
},
|
|
{
|
|
text: "Configuration",
|
|
items: [
|
|
{ text: "Deployment & Docker", link: "/config/deployment" },
|
|
{ text: "Environment Variables", link: "/config/env" },
|
|
{ text: "Authentication", link: "/config/authentication" },
|
|
{ text: "OIDC / SSO", link: "/config/oidc" },
|
|
{ text: "OIDC Config Examples", link: "/config/oidc-config-examples" },
|
|
{ text: "Admin Settings", link: "/config/admin-settings" },
|
|
{ text: "WOPI (Office Editing)", link: "/config/wopi" },
|
|
],
|
|
},
|
|
{
|
|
text: "Features",
|
|
items: [
|
|
{ text: "WebDAV", link: "/guide/webdav" },
|
|
{ text: "CalDAV & CardDAV", link: "/guide/caldav-carddav" },
|
|
{ text: "DAV Client Setup", link: "/guide/dav-client-setup" },
|
|
{ text: "Chunked Uploads", link: "/guide/chunked-uploads" },
|
|
{ text: "Batch Operations", link: "/guide/batch-operations" },
|
|
{ text: "Deduplication", link: "/guide/deduplication" },
|
|
{ text: "Favorites & Recent", link: "/guide/favorites-and-recent" },
|
|
{ text: "Search", link: "/guide/search" },
|
|
{ text: "Thumbnails & Transcoding", link: "/guide/thumbnails-and-transcoding" },
|
|
{ text: "Trash & Recycle Bin", link: "/guide/trash" },
|
|
{ text: "ZIP & Compression", link: "/guide/zip-and-compression" },
|
|
{ text: "Internationalization", link: "/guide/i18n" },
|
|
],
|
|
},
|
|
{
|
|
text: "Architecture",
|
|
items: [
|
|
{ text: "Internal Architecture", link: "/architecture/" },
|
|
{ text: "Caching", link: "/architecture/caching" },
|
|
{ text: "Resource Listing API", link: "/architecture/resource-listing" },
|
|
{ text: "Storage Safety", link: "/architecture/file-system-safety" },
|
|
{ text: "Database Transactions", link: "/architecture/database-transactions" },
|
|
{ text: "ReBAC Authorization", link: "/architecture/rebac-authorization" },
|
|
{ text: "Share Integration", link: "/architecture/share-integration" },
|
|
{ text: "Storage Quotas", link: "/architecture/storage-quotas" },
|
|
{ text: "File and Blob lifecycle", link: "/architecture/file-and-blob-lifecycle" },
|
|
{ text: "ReBAC & Authorization", link: "/architecture/rebac-authorization" },
|
|
{ text: "User lifecycle", link: "/architecture/user-lifecycle" },
|
|
{ text: "Authentication model", link: "/architecture/auth-model" },
|
|
{ text: "Magic-link auth", link: "/architecture/magic-link-auth" },
|
|
],
|
|
},
|
|
{ text: "FAQ", link: "/faq" },
|
|
],
|
|
},
|
|
|
|
socialLinks: [
|
|
{ icon: "github", link: "https://github.com/DioCrafts/OxiCloud" },
|
|
],
|
|
|
|
footer: {
|
|
message: "Released under the MIT License.",
|
|
copyright: "Copyright © 2025-present DioCrafts",
|
|
},
|
|
},
|
|
});
|