docs: 补充钉钉 OAuth2 部署配置说明

Signed-off-by: konglong87 <38234954+konglong87@users.noreply.github.com>
This commit is contained in:
konglong87 2026-06-02 16:43:42 +08:00
parent d89fa32c2d
commit 7cf5b8af8d
4 changed files with 34 additions and 0 deletions

View file

@ -51,6 +51,9 @@ SkillHub 通过环境变量进行配置,主要配置项如下:
|---------|------|--------|
| `OAUTH2_GITHUB_CLIENT_ID` | GitHub OAuth Client ID | - |
| `OAUTH2_GITHUB_CLIENT_SECRET` | GitHub OAuth Client Secret | - |
| `OAUTH2_DINGTALK_CLIENT_ID` | 钉钉 OAuth AppKey | - |
| `OAUTH2_DINGTALK_CLIENT_SECRET` | 钉钉 OAuth AppSecret | - |
| `OAUTH2_DINGTALK_DISPLAY_NAME` | 钉钉登录按钮显示名 | `钉钉` |
### 首登管理员配置

View file

@ -19,6 +19,20 @@ SkillHub 支持多种认证方式,满足不同企业的安全需求。
OAUTH2_GITHUB_CLIENT_SECRET=your-client-secret
```
### 钉钉 OAuth2
1. 在[钉钉开放平台](https://open-dev.dingtalk.com/)创建 H5 微应用,获取 AppKey 和 AppSecret
2. 开通 `Contact.User.Read` 权限(获取用户信息)
3. 发布应用版本以激活 OAuth2 凭证
4. 回调地址填写 `{baseUrl}/login/oauth2/code/dingtalk`
5. 配置环境变量:
```bash
OAUTH2_DINGTALK_CLIENT_ID=你的AppKey
OAUTH2_DINGTALK_CLIENT_SECRET=你的AppSecret
```
> 钉钉使用 `corpid` scope(非标准 OIDC `openid`),用户以 `unionId` 作为唯一标识。
### 扩展 OAuth Provider
架构支持扩展其他 OAuth Provider,如 GitLab、Gitee 等。

View file

@ -51,6 +51,9 @@ SkillHub is configured through environment variables. The main configuration ite
|---------------------|-------------|---------------|
| `OAUTH2_GITHUB_CLIENT_ID` | GitHub OAuth Client ID | - |
| `OAUTH2_GITHUB_CLIENT_SECRET` | GitHub OAuth Client Secret | - |
| `OAUTH2_DINGTALK_CLIENT_ID` | DingTalk OAuth AppKey | - |
| `OAUTH2_DINGTALK_CLIENT_SECRET` | DingTalk OAuth AppSecret | - |
| `OAUTH2_DINGTALK_DISPLAY_NAME` | DingTalk login button display name | `钉钉` |
### Bootstrap Admin Configuration

View file

@ -19,6 +19,20 @@ SkillHub supports multiple authentication methods to meet different enterprise s
OAUTH2_GITHUB_CLIENT_SECRET=your-client-secret
```
### DingTalk OAuth2
1. Create an H5 micro-app on [DingTalk Open Platform](https://open-dev.dingtalk.com/) and obtain AppKey and AppSecret
2. Enable the `Contact.User.Read` permission (required for fetching user info)
3. Publish the app version to activate OAuth2 credentials
4. Set the callback URL to `{baseUrl}/login/oauth2/code/dingtalk`
5. Configure environment variables:
```bash
OAUTH2_DINGTALK_CLIENT_ID=your-appkey
OAUTH2_DINGTALK_CLIENT_SECRET=your-appsecret
```
> DingTalk uses `corpid` scope (not standard OIDC `openid`). Users are identified by `unionId`.
### Extend OAuth Provider
The architecture supports extending to other OAuth providers like GitLab, Gitee, etc.