Add a password-gated private instance mode for xaigen.

Keep Authentik on aigen, isolate library data per instance, and purge Comfy outputs from the desktop after they are saved on the server.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Towsty
2026-08-25 19:24:00 -05:00
co-authored by Cursor
parent e2db183a8e
commit bc0ea613c1
22 changed files with 426 additions and 15 deletions
+1 -1
View File
@@ -1,5 +1,5 @@
export default defineEventHandler(async (event) => {
if (!authEnabled()) {
if (!oidcAuthEnabled()) {
throw createError({ statusCode: 404, statusMessage: 'Auth is not enabled' })
}
const config = useRuntimeConfig()
+17
View File
@@ -0,0 +1,17 @@
export default defineEventHandler(async (event) => {
if (!passwordAuthEnabled()) {
throw createError({ statusCode: 404, statusMessage: 'Password login is not enabled' })
}
const user = getSessionUser(event)
if (!user) throw createError({ statusCode: 401, statusMessage: 'Authentication required' })
const body = await readBody<{ username?: string; password?: string; currentPassword?: string }>(event)
const current = String(body?.currentPassword || '')
const nextUser = String(body?.username || '').trim()
const nextPass = String(body?.password || '')
if (!current) throw createError({ statusCode: 400, statusMessage: 'Current password is required' })
const matched = await verifyLocalLogin(publicUsername() || user.name || '', current)
if (!matched) throw createError({ statusCode: 401, statusMessage: 'Current password is incorrect' })
const updated = await updateCredentials(nextUser || matched, nextPass || current)
setSessionUser(event, { sub: user.sub, name: updated.username })
return { ok: true, username: updated.username }
})
+5 -1
View File
@@ -1,5 +1,9 @@
export default defineEventHandler(async (event) => {
if (!authEnabled()) {
if (passwordAuthEnabled()) {
await sendRedirect(event, '/login', 302)
return
}
if (!oidcAuthEnabled()) {
throw createError({ statusCode: 404, statusMessage: 'Auth is not enabled' })
}
const config = useRuntimeConfig()
+17
View File
@@ -0,0 +1,17 @@
export default defineEventHandler(async (event) => {
if (!passwordAuthEnabled()) {
throw createError({ statusCode: 404, statusMessage: 'Password login is not enabled' })
}
assertLoginAllowed(event)
const body = await readBody<{ username?: string; password?: string }>(event)
const username = String(body?.username || '')
const password = String(body?.password || '')
const matched = await verifyLocalLogin(username, password)
if (!matched) {
recordLoginFailure(event)
throw createError({ statusCode: 401, statusMessage: 'Incorrect username or password' })
}
clearLoginFailures(event)
setSessionUser(event, { sub: `local:${privateInstanceId()}`, name: matched })
return { ok: true, user: { name: matched } }
})
+6 -1
View File
@@ -1,4 +1,9 @@
export default defineEventHandler((event) => {
const user = getSessionUser(event)
return { user, authEnabled: authEnabled() }
return {
user,
authEnabled: authEnabled(),
authMode: passwordAuthEnabled() ? 'password' : oidcAuthEnabled() ? 'oidc' : 'none',
instanceName: useRuntimeConfig().public.instanceName || 'AIGen'
}
})