headscale: support PKCE verifier

The headscale 0.24.0 introduced support for PKCE verifier. Add options
to set these parameters in the config.
This commit is contained in:
Andrey Albershteyn
2025-07-21 16:48:18 +02:00
parent 4b44b24041
commit 13a041b174
@@ -406,6 +406,31 @@ in
'';
example = [ "alice@example.com" ];
};
pkce = {
enabled = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
Enable or disable PKCE (Proof Key for Code Exchange) support.
PKCE adds an additional layer of security to the OAuth 2.0
authorization code flow by preventing authorization code
interception attacks
See https://datatracker.ietf.org/doc/html/rfc7636
'';
example = true;
};
method = lib.mkOption {
type = lib.types.str;
default = "S256";
description = ''
PKCE method to use:
- plain: Use plain code verifier
- S256: Use SHA256 hashed code verifier (default, recommended)
'';
};
};
};
tls_letsencrypt_hostname = lib.mkOption {