# Otherwise, this can be set as a specific URL endpoint.
OIDC_END_SESSION_ENDPOINT=false
+# Enable fetching of the user's avatar from the 'picture' claim on login.
+# Will only be fetched if the user doesn't already have an avatar image assigned.
+# By default this is false which disables avatar fetching. Set to 'true' to enable.
+# WARNING: This can be a security risk due to performing server-side fetching
+# (with up to 3 redirects) of data from external URLs. Only enable if you
+# trust the OIDC auth provider to provide safe URLs for user images.
+OIDC_FETCH_AVATAR=false
+
# Enable auto-discovery of endpoints and token keys.
# As per the standard, expects the service to serve a
# `<issuer>/.well-known/openid-configuration` endpoint.