- Google:授权码流程(openid email profile),handle 优先用已验证邮箱,头像取 picture - Telegram:官方 widget 直接回传签名资料,后端按官方算法验签(secret=SHA256(bot_token),除 hash 外全字段排序比对)+ auth_date 24h 时效 - providers 列表自动按配置下发(未配置的不显示);widget 型带 bot 用户名 - 三个登录方式共用读者会话与 upsert;Telegram 走 POST 无跳转 - .env.example 补 ONE_GOOGLE_* / ONE_TELEGRAM_* 模板
21 lines
741 B
Bash
21 lines
741 B
Bash
AccessKey=
|
||
SecretAccessKey=
|
||
S3Api="https://<account_id>.r2.cloudflarestorage.com"
|
||
PublicURL=
|
||
Bucket=
|
||
|
||
# GitHub OAuth(评论登录):https://github.com/settings/developers
|
||
# 回调地址填 http://localhost:8080/api/auth/callback/github(线上换成正式域名)
|
||
ONE_GITHUB_CLIENT_ID=
|
||
ONE_GITHUB_CLIENT_SECRET=
|
||
|
||
# Telegram 登录(Login Widget):@BotFather 建 bot 拿 token,
|
||
# 再用 /setdomain 把域名登记给 bot(本地开发填 localhost)
|
||
ONE_TELEGRAM_BOT=
|
||
ONE_TELEGRAM_BOT_TOKEN=
|
||
|
||
# Google 登录:https://console.cloud.google.com/apis/credentials 建 OAuth 客户端,
|
||
# 回调地址填 http://localhost:8080/api/auth/callback/google(线上换成正式域名)
|
||
ONE_GOOGLE_CLIENT_ID=
|
||
ONE_GOOGLE_CLIENT_SECRET=
|