1
[Feature] Trusted Local Provisioning for Immich
Source: immich-app/immich#28792 · opened by @caniko
I have searched the existing feature requests, both open and closed, to make sure this is not a duplicate request. • Yes The feature Summary Add immich-admin provision-token, a server-local command that mints a short-lived admin session token for infrastructure automation running on the Immich host. The token is a normal Immich session token. It is then used against the existing admin API. Also allow UserAdminCreateDto.password to be omitted when OAuth is enabled. Together, these changes let declarative operators manage Immich users and OIDC without storing a long-lived admin API key, scraping the UI, or writing directly to the database. Motivation Immich already supports most of the surfaces a declarative operator needs. System settings can come from IMMICH_CONFIG_FILE, OAuth settings are part of normal system config, and users can be reconciled through the admin API. The missing piece is bootstrap authentication for automation that already controls the…
No pledges yet. Be the first to back this.
Comments
Similar requests
[Feature] Import shared immich link to my immich
37 votes · 0 comments
Support reverse-proxy trusted header authentication (SSO behind Authelia / Authentik / oauth2-proxy)
1 vote · 0 comments
[Feature] Free Up Space (Android App Feature) Dangerously Broadens Deletion Scope by Default: Adjust This
6 votes · 0 comments
[Feature] Improve CLI experience
1 vote · 0 comments
[Feature] Show local photos immediately on mobile app startup without waiting for server sync
6 votes · 0 comments
No comments yet.