Skip to content

oidc: add option to disable automatic account creation - #248

Open
jaroslaw-dutka wants to merge 1 commit into
sol1:mainfrom
jaroslaw-dutka:f/limit-oidc-login
Open

jaroslaw-dutka wants to merge 1 commit into
sol1:mainfrom
jaroslaw-dutka:f/limit-oidc-login

Conversation

@jaroslaw-dutka

Copy link
Copy Markdown
Contributor

With [oidc] auto_create_users = false, OIDC login no longer creates an account for a user who isn't in the database yet. Only users an admin has added beforehand can log in. The option defaults to true, so existing deployments behave as before.

An admin can add users ahead of their first login with any of:

  • CLI: rustguac add-user --email <email> --role <role> [--name <name>]
  • API: POST /api/users (admin only), returns 201, or 409 if the user exists
  • Admin page: an "Add User" form under the users table

A user added this way keeps the role the admin gave them; default_role is not applied. Group-to-role mappings still apply on every login.

A rejected SSO login now redirects to the login page with an error code instead of returning JSON. This covers a user with no account (sso_error=no_account) and a disabled account (sso_error=disabled). SSO errors are now shown under the SSO button: they used to go into the API key form, which is hidden when SSO is on, so "SSO login failed" was never visible. The "provider unavailable" notice uses the same element, and all SSO messages are defined in one place in index.html.

an account for a user who isn't in the database yet. Only users an
admin has added beforehand can log in. The option defaults to true, so
existing deployments behave as before.

An admin can add users ahead of their first login with any of:
- CLI: `rustguac add-user --email <email> --role <role> [--name <name>]`
- API: `POST /api/users` (admin only), returns 201, or 409 if the user exists
- Admin page: an "Add User" form under the users table

A user added this way keeps the role the admin gave them; default_role
is not applied. Group-to-role mappings still apply on every login.

A rejected SSO login now redirects to the login page with an error code
instead of returning JSON. This covers a user with no account
(sso_error=no_account) and a disabled account (sso_error=disabled).
SSO errors are now shown under the SSO button: they used to go into the
API key form, which is hidden when SSO is on, so "SSO login failed" was
never visible. The "provider unavailable" notice uses the same element,
and all SSO messages are defined in one place in index.html.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant