plausible_ce_oidc
OIDC authorization-code login for Plausible Community Edition v2.1.4.
CE does not load auth plugins at runtime. Add this package to the Plausible mix.exs and name it from the router, then build with MIX_ENV=ce.
From the root of a Plausible CE v2.1.4 checkout:
git apply path/to/plausible_ce_oidc/priv/plausible-v2.1.4.patch
priv/plausible-v2.1.4.patch ships with this package. It adds this dependency and the router lines below. The dependency is the Hex package, so the checkout can live anywhere.
{:plausible_ce_oidc, "~> 0.1.0", only: [:ce, :ce_dev, :ce_test]}
plug(PlausibleCeOidc.FirstLaunchPlug, redirect_to: "/register")
plug PlausibleCeOidc.LoginPlug
get "/auth/oidc", PlausibleCeOidc.Controller, :start, alias: false
get "/auth/oidc/callback", PlausibleCeOidc.Controller, :callback, alias: false
LoginPlug goes after PlausibleWeb.AuthPlug. FirstLaunchPlug replaces PlausibleWeb.FirstLaunchPlug so the OAuth callback is not redirected to /register on an empty database. alias: false is required because those routes sit inside scope "/", PlausibleWeb. Without it Phoenix looks up PlausibleWeb.PlausibleCeOidc.Controller and /auth/oidc returns 500. The patch does not mount the UI under a path. PlausibleCeOidc.ScriptNamePlug can prefix root-relative href, action, and Location values with the BASE_URL path when a host inserts it. A path mount also needs the LiveView socket to keep that path, and a click handler for links LiveView redraws as /sites/new. Those edits stay with the host.
Set OIDC_ISSUER_URL, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET, and OIDC_REDIRECT_URI. Leave any of them empty and CE email login stays in place. The email claim is the Plausible address. sub is the PDS DID. Login fails when the email claim is missing. A previous {handle}@users.support.test account is moved onto that address. A picture claim is stored under PLAUSIBLE_OIDC_AVATAR_DIR (default /var/lib/plausible/oidc-avatars) and served from /avatar/:hash.
/login?password=1 keeps the email form. /js/script.js and /api/event are not in the browser pipeline.
Publish
pnpm run package:plausible-ce-oidc
HEX_API_KEY="$(op read 'op://FileOrbit/FileOrbit/add more/HEX_PM_API_KEY')" pnpm run publish:plausible-ce-oidc
License
GNU Affero General Public License v3.0 or any later version, the same terms as Plausible Community Edition. See LICENSE.md.