Self-hosted AI workspace.
Find a file
holden093 739eb0faf1 fix(oidc): serialize admin bootstrap, atomic key creation, guard against silent demotion
Three fixes from second review pass:

1. (security) Serialize the first-OIDC-user admin bootstrap inside
   _config_lock.  Previously the  check and username
   collision resolution happened outside the lock, so two concurrent
   first-login callbacks could both observe an empty user map and
   both persist as admin.  Now idempotent lookup, bootstrap decision,
   and collision resolution are all inside one critical section.

2. (auth) Make data/.app_key creation atomic via O_EXCL open so two
   racing workers on a fresh deployment cannot generate different
   keys.  The loser reads the winner's key, guaranteeing every worker
   shares the same Fernet key for OIDC state encryption.

3. (auth) Track whether UserInfo was successfully fetched
   (_userinfo_available flag in claims).  The callback now skips
   admin group sync for existing users when UserInfo is unavailable
   AND the id_token lacks a groups claim — a transient provider
   failure no longer silently demotes existing OIDC admins.  When
   UserInfo succeeds or the id_token carries groups, admin status
   syncs as before.

Regression tests: concurrent admin bootstrap, key-creation race,
UserInfo-unavailable preserves admin, UserInfo-available demotes,
id_token groups authoritative without UserInfo.
2026-07-25 18:32:56 +02:00
.github ci: add CodeQL advanced setup to scan pull requests before merge (#5250) 2026-07-21 10:18:06 -07:00
companion fix(companion): require chat scope for model inventory (#4319) 2026-06-16 01:15:05 +02:00
config/searxng Generate SearXNG secret on first boot 2026-06-01 11:03:02 +09:00
core fix(oidc): serialize admin bootstrap, atomic key creation, guard against silent demotion 2026-07-25 18:32:56 +02:00
docker fix(docker): make host Docker socket opt-in (#4902) 2026-06-30 19:54:51 +02:00
docs ci: add CodeQL advanced setup to scan pull requests before merge (#5250) 2026-07-21 10:18:06 -07:00
integrations Add Codex and Claude document draft integration 2026-06-09 14:27:53 +09:00
licenses feat(a11y): add a Text size control and an OpenDyslexic font option (#4210) 2026-06-22 13:53:46 +02:00
mcp_servers Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
routes fix(oidc): serialize admin bootstrap, atomic key creation, guard against silent demotion 2026-07-25 18:32:56 +02:00
scripts Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
services Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
specs chore: update repository URLs after organization transfer (#5622) 2026-07-20 16:43:47 +02:00
src fix(oidc): serialize admin bootstrap, atomic key creation, guard against silent demotion 2026-07-25 18:32:56 +02:00
static fix(oidc): surface callback errors on login page from URL query param 2026-07-25 18:32:56 +02:00
swift/odysseus-mlx-image-bridge Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
tests fix(oidc): serialize admin bootstrap, atomic key creation, guard against silent demotion 2026-07-25 18:32:56 +02:00
.dockerignore fix(devops): harden docker config defaults (#4349) 2026-06-16 04:03:43 +01:00
.env.example fix(oidc): address review items — aud arrays, JWKS cache, alg pinning, redirect_uri, stateless state, first-user-admin 2026-07-25 18:32:56 +02:00
.gitattributes Add native Windows compatibility layer 2026-06-01 15:09:47 +09:00
.gitignore pwa missing icons added (#428) 2026-06-15 16:00:13 +09:00
ACKNOWLEDGMENTS.md feat(a11y): add a Text size control and an OpenDyslexic font option (#4210) 2026-06-22 13:53:46 +02:00
app.py feat(auth): add generic OpenID Connect (OIDC) single sign-on 2026-07-25 18:32:56 +02:00
build-macos-app.sh macOS app: force native arm64 uvicorn on Apple Silicon 2026-06-02 20:56:53 +09:00
build-windows-portable.ps1 feat(launcher): add portable windows launcher (#976) 2026-06-16 04:58:16 +01:00
CONTRIBUTING.md chore: update repository URLs after organization transfer (#5622) 2026-07-20 16:43:47 +02:00
docker-compose.gpu-amd.yml fix(oidc): add missing OIDC_REDIRECT_URI and OIDC_FIRST_USER_IS_ADMIN to compose files 2026-07-25 18:32:56 +02:00
docker-compose.gpu-nvidia.yml fix(oidc): add missing OIDC_REDIRECT_URI and OIDC_FIRST_USER_IS_ADMIN to compose files 2026-07-25 18:32:56 +02:00
docker-compose.yml fix(oidc): add missing OIDC_REDIRECT_URI and OIDC_FIRST_USER_IS_ADMIN to compose files 2026-07-25 18:32:56 +02:00
Dockerfile Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
install-service.sh Odysseus v1.0 2026-05-31 23:58:26 +09:00
launch-windows.ps1 feat(launcher): add portable windows launcher (#976) 2026-06-16 04:58:16 +01:00
launcher.py feat(launcher): add portable windows launcher (#976) 2026-06-16 04:58:16 +01:00
LICENSE chore: backport main-only changes to dev AGPL relicense + Cookbook serve fix (#3704) 2026-06-09 23:20:34 +02:00
odysseus-ui.service fix: systemd service should serve on port 7000 to match Docker/setup/README (#1297) 2026-06-03 02:04:37 +09:00
Odysseus.spec feat(launcher): add portable windows launcher (#976) 2026-06-16 04:58:16 +01:00
package-lock.json chore(deps): remove unused @anthropic-ai/sdk dependency (#4566) 2026-06-19 09:40:35 +02:00
package.json chore: update repository URLs after organization transfer (#5622) 2026-07-20 16:43:47 +02:00
pyproject.toml test: add fast lane and duration visibility (#3659) 2026-06-09 20:11:47 +02:00
README.md chore: update repository URLs after organization transfer (#5622) 2026-07-20 16:43:47 +02:00
requirements-optional.txt chore(deps): bump the python group with 3 updates (#3991) 2026-06-15 19:25:15 +09:00
requirements.txt feat(auth): add generic OpenID Connect (OIDC) single sign-on 2026-07-25 18:32:56 +02:00
ROADMAP.md Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
SECURITY.md Clarify private deployment hardening docs 2026-06-02 13:01:12 +09:00
setup.py fix(setup): load .env so a pre-seeded admin password is honored on native installs (#4787) 2026-06-23 20:08:05 +02:00
start-macos.sh fix(macos): rebuild incomplete venv instead of failing on re-run (#3106) 2026-06-15 16:12:19 +09:00
THREAT_MODEL.md docs: add THREAT_MODEL.md (#1111) 2026-06-02 22:40:37 +09:00
update_windows.bat Windows: add Docker update script 2026-06-02 20:45:32 +09:00

Odysseus

A self-hosted AI workspace for chat, agents, research, documents, email, notes, calendar, and local model workflows.

Quick Start · Setup Guide · Contributing · Roadmap

Packaging status

Odysseus interface


Quick Start

dev is the default branch and gets the newest changes first. Use main if you want the more curated branch.

git clone https://github.com/odysseus-dev/odysseus.git
cd odysseus
cp .env.example .env
docker compose up -d --build

Open http://localhost:7000 when the containers are healthy. The first admin password is printed in docker compose logs odysseus.

Native installs, GPU notes, Windows/macOS instructions, HTTPS, and configuration live in the setup guide.

Features

  • Chat + Agents — local/API models, tools, MCP, files, shell, skills, and memory.
  • Cookbook — hardware-aware model recommendations, downloads, and serving.
  • Deep Research — multi-step web research with source reading and report generation.
  • Compare — blind side-by-side model testing and synthesis.
  • Documents — writing-first editor with AI edits, suggestions, Markdown, HTML, CSV, and syntax highlighting.
  • Email — IMAP/SMTP inbox with triage, tags, summaries, reminders, and reply drafts.
  • Notes, Tasks + Calendar — reminders, todos, scheduled agent tasks, and CalDAV sync.
  • Extras — gallery/image editor, themes, uploads, web search, presets, sessions, and 2FA.

Demo

A full hover-to-play tour lives on the landing page: docs/index.html.

Contributing

Help is welcome. The best entry points are fresh-install testing, provider setup bugs, mobile/editor polish, docs, and small focused refactors. See CONTRIBUTING.md and ROADMAP.md.

Security

Odysseus is a self-hosted workspace with powerful local tools. Keep auth enabled, keep private data out of Git, and do not expose raw model/service ports publicly. Deployment details are in the setup guide.

Star History

Star History Chart

License

AGPL-3.0-or-later -- see LICENSE and ACKNOWLEDGMENTS.md.