Repository navigation
Conversation
✅ Deploy Preview for authentik-storybook ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for authentik-integrations ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for authentik-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
❌ 15 Tests Failed:
View the top 3 failed test(s) by shortest run time
To view more test analytics, go to the Test Analytics Dashboard |
|
authentik PR Installation instructions Instructions for docker-composeAdd the following block to your AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-7b025acae2626f3a6ec70750ca8370f3e722a15f
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)sAfterwards, run the upgrade commands from the latest release notes. Instructions for KubernetesAdd the following block to your authentik:
outposts:
container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
image:
repository: ghcr.io/goauthentik/dev-server
tag: gh-7b025acae2626f3a6ec70750ca8370f3e722a15fAfterwards, run the upgrade commands from the latest release notes. |
|
we should have a longer discussion about this before actually implementing anything. My thinking is as follows, following along the lines of #24961 :
|
|
Marking as draft for now, will also discuss with G |
5c0be0f to
420c3e3
Compare
BeryJu
left a comment
There was a problem hiding this comment.
- Smaller PR pls
- First PR that adds the system
- Second PR that adds the usage
- Have to remove the migrations that remove the old fields, those need to wait until 27.2
- Move secret model next to crypto ....maybe
2302afa to
8cdc877
Compare
e5ebe2d to
2f59f70
Compare
# Conflicts: # web/test/browser/700-applications.test.ts # web/test/browser/ak-mdx.test.ts
These test and outpost fixes do not depend on managed secrets and main has since fixed the provider toolbar ambiguity the browser tests worked around. They can land separately.
DRF ignores unknown fields, so a blueprint or API client that still sends client_secret would apply cleanly and leave the provider with a generated secret. Fail with a pointer to the reference field instead, until the legacy columns are removed in 2027.2.
Multi-line text described an input widget, not the content, so every JSON consumer had to parse and validate the value itself. A JSON secret is now validated when it is saved, text values may span several lines, and only text can be generated or rotated. The enterprise audit log records model diffs and hides fields by name. "value" matched none of the hidden names, so creating a secret wrote its plaintext into the event. The field is now secret_value; the API keeps value. Rotation uses permission_required like other custom actions, and the validation hook consumers use to veto a value now lives here with the model that sends it.
Creating a text secret without a value can ask for a length, and otherwise uses the default token length. Rotating keeps at least the current length, so a secret a consumer generated with its own length, such as a 128 character OAuth2 client secret, doesn't shrink to the default. Generated values use ASCII letters and digits, which every consumer accepts, so there is no character set option.
Deleting an object that a PROTECT foreign key references fails, but used_by reported those relations as cascading, so delete dialogs said the referencing objects would be deleted too. Secrets are protected by every object that uses them, so this would have shown for each one.
Serializers only check that a user may attach a secret when they have a request, and the importer runs them without one. The application wizard and blueprint uploads check permissions up front instead, so they now also require "View secret's value" on every existing secret the blueprint references. Without it, a user who may create a SCIM provider could point it at their own server with any secret's UUID.
Each consumer repeated whether its secret is required, optional, or generated when the object is created, in serializer arguments and validators. The reference field now reads it from the model: a blank reference is optional on create, and one that can't be null must stay set on update. JSON consumers pass allowed_types like every other consumer instead of using a subclass.
Details
What does this PR change?
Adds managed secrets: a
Secretmodel with its own API under System > Secrets. This is the first PR of a stack. The PRs above it move each object's credentials into secrets, then add the Admin pages and docs.lengthsets the size of a generated value.<old field>_reffields. Attaching a secret needs permission to view its value, including through blueprints imported by users and the application wizard. Old credential field names fail with an error that names the replacement.used_byreports protected relations, so the delete dialog no longer claims that objects using a secret will be deleted.Values are stored unencrypted, as the credentials were before.
Stack:
Why is this change needed?
Credentials were columns on each object. They couldn't be shared, permissioned separately from the object, rotated, or audited.
How was this tested?
Added tests for each secret type, generation and rotation lengths, the view, replace and rotate permissions, and that values never reach API responses or the enterprise audit log. Also tests that blueprint imports and the application wizard refuse secrets the user can't view. Ran the full stack locally and rotated a proxy cookie secret from the Admin interface. The new value kept the minimum length, the rotation was recorded, and no event contains the value.
Linked issues
Checklist
make all)make docs)