feather-reader 0.3.10

A minimalist, atproto-native RSS/Atom reader in Rust — your feed subscriptions live in your own PDS.
Documentation
# OAuth routing — RUST backend (FEATHERREADER_REPO_BACKEND=rust).
#
# Selected by container-entrypoint.sh and imported by the Caddyfile. The
# matching file for the other backend is caddy-oauth-sidecar.conf; exactly one
# is ever installed as /etc/caddy/oauth-routes.conf.
#
# WHY THIS IS A DEPLOY-TIME CHOICE AND NOT A RUNTIME ONE
#
# The two backends cannot share /oauth/callback. Both receive the PDS's redirect
# with exactly `?code=&state=&iss=` — identical parameters, because the PDS is
# responding to the same client_id with the same redirect_uri in both cases.
# Nothing in the request distinguishes them, so the edge cannot route on content
# the way the sidecar hand-off could. One process has to own the path.
#
# That is why this file is selected from FEATHERREADER_REPO_BACKEND rather than
# routed dynamically: the flag and the routing must agree, or logins break in a
# way that looks like a PDS outage. Repo operations remain switchable purely at
# runtime — only the login path is pinned by this choice.
#
# NO PREFIX STRIP. The app serves these paths literally, because the published
# client_id IS https://<host>/oauth/client-metadata.json and every URL in that
# document is built from the same /oauth base.

handle /oauth/* {
	reverse_proxy 127.0.0.1:8082 {
		header_up -X-Origin-Auth
	}
}