Skip to content

功能建议:支持使用 OIDC 身份令牌调用 API(或提供令牌交换端点) #7617

Description

@Pahkho

Read This First

已阅读提交前必读、官方文档与 README;本 issue 是功能建议,非使用/配置类问题。

概述

New API 已支持 OIDC 登录(网页端),但 HTTP API(/api/*)只认自家凭证(系统访问令牌或 session cookie)。在自部署且已有统一身份源(IdP)的场景下,服务端集成手里持有该用户的有效 OIDC 令牌,却无法以此用户身份调用 API。

实测(授权端点、JWKS、userinfo 均已验证可用):

GET /api/user/self   Authorization: Bearer <OIDC access token>
→ {"code":"AUTH_UNAUTHORIZED","message":"Unauthorized, invalid access token"}

建议(任一形态均可解决)

  1. /api/* 直接认可 OIDC 令牌:增加设置项(默认关闭)配置 IdP 的 issuer/JWKS;开启后校验 Authorization: Bearer <oidc-token>,按 oidc_id 映射到本地用户(OIDC 登录本来就在维护这个映射),以该用户身份鉴权。可附带 scope 限制。
  2. 或提供一个令牌交换端点:如 POST /api/oauth/exchange,校验 OIDC 令牌后签发该用户的 session/access token——不改动现有鉴权中间件,给集成方一个单一桥接点。

使用场景

自部署 + 统一 IdP(Casdoor/Keycloak 等)的场景:桌面端、嵌入式客户端通过 IdP 完成用户认证后,中间层服务需要以用户个人身份访问 API——余额展示(/api/user/self)、个人日志(/api/log/self)等,实现按用户审计;而不是共享一个管理员令牌。目前的替代方案只有“每个用户手动生成并登记系统访问令牌”或“持有管理员凭据模拟登录”,这两种都不符合以 IdP 为中心的认证流程。

Your current newapi version

rc-38

Submission Checks

  • Non-duplicate issue: I have searched existing Issues and confirmed there are no similar issues.
  • Read this first: I have fully read the section above, reviewed the docs at https://docs.newapi.ai/ and the project README, and asked AI first, confirming this is not a usage, configuration, or integration question, and that the current version cannot meet my needs.
  • Supported version: I have provided an exact version, commit, or image tag (not latest or unknown) and confirm this feature request is for an unmodified, supported version from this repository.
  • Not a third-party service: I confirm that this request is not exclusive to a third-party hosting site, relay, API service, or fork that has not been verified against the unmodified repository. Third-party instance issues must be reported to their operator.
  • Not pass-through: I confirm this is not a forwarding report after enabling pass-through; pass-through sends content as-is and does not go through new-api processing logic.
  • Channel and protocol boundary: I confirm this is not a feature request for a Coding Plan service, reverse-engineered channel, third-party API wrapper, Codex reverse-proxy endpoint, or treating Codex API-specific behavior as standard OpenAI API behavior. If first observed through such an interface, I have based the request on a standard API protocol supported by this repository.
  • Template intact: I have not removed any guidance or section headings from this template and will complete it as requested.
  • Maintainer time: I understand that maintainers have limited time. Do not paste unfiltered AI-generated text in the issue body or in later comments; extract the points needed for review first. Submissions that do not follow this template, or that omit the necessary points and cannot be reviewed, may be ignored or closed. Repeated submissions of this kind may result in a block.

Feature Description

  1. /api/* 直接认可 OIDC 令牌:增加设置项(默认关闭)配置 IdP 的 issuer/JWKS;开启后校验 Authorization: Bearer <oidc-token>,按 oidc_id 映射到本地用户(OIDC 登录本来就在维护这个映射),以该用户身份鉴权。可附带 scope 限制。
  2. 或提供一个令牌交换端点:如 POST /api/oauth/exchange,校验 OIDC 令牌后签发该用户的 session/access token——不改动现有鉴权中间件,给集成方一个单一桥接点。

Use Case

自部署 + 统一 IdP(Casdoor/Keycloak 等)的场景:桌面端、嵌入式客户端通过 IdP 完成用户认证后,中间层服务需要以用户个人身份访问 API——余额展示(/api/user/self)、个人日志(/api/log/self)等,实现按用户审计;而不是共享一个管理员令牌。目前的替代方案只有“每个用户手动生成并登记系统访问令牌”或“持有管理员凭据模拟登录”,这两种都不符合以 IdP 为中心的认证流程。

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions