An Ory Hydra authentication and authorization provider.
Caution
This server implements no rate limiting on its own, make sure rate limiting is configured in your reverse proxy, specifically on /login.
JVM: ./gradlew shadowJar
GraalVM Native: ./gradlew nativeCompile
Copy application.yml.example, rename it to whatever you like, fill it in and run the server binary with MICRONAUT_CONFIG_FILES=path/to/your/application.yml.
Run the server binary with --initialSetup.adminUuid=your-uuid-here.
- Set
micronaut.server.client-address-header(e.g.X-Forwarded-For) and have the proxy overwrite it. The Minecraft IP check uses it. - Set
micronaut.server.host-resolution.protocol-header: X-Forwarded-Protoso the OAuthredirect_uriishttps://. - Don't use
micronaut.server.context-path, the OAuth login/callback routes ignore it. Strip the prefix in the proxy instead and also proxy/oauth/to Staff-Auth.