Repository navigation
oidc: add option to disable automatic account creation - #248
Open
jaroslaw-dutka wants to merge 1 commit into
Open
jaroslaw-dutka wants to merge 1 commit into
jaroslaw-dutka wants to merge 1 commit into
Conversation
an account for a user who isn't in the database yet. Only users an admin has added beforehand can log in. The option defaults to true, so existing deployments behave as before. An admin can add users ahead of their first login with any of: - CLI: `rustguac add-user --email <email> --role <role> [--name <name>]` - API: `POST /api/users` (admin only), returns 201, or 409 if the user exists - Admin page: an "Add User" form under the users table A user added this way keeps the role the admin gave them; default_role is not applied. Group-to-role mappings still apply on every login. A rejected SSO login now redirects to the login page with an error code instead of returning JSON. This covers a user with no account (sso_error=no_account) and a disabled account (sso_error=disabled). SSO errors are now shown under the SSO button: they used to go into the API key form, which is hidden when SSO is on, so "SSO login failed" was never visible. The "provider unavailable" notice uses the same element, and all SSO messages are defined in one place in index.html.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
With
[oidc] auto_create_users = false, OIDC login no longer creates an account for a user who isn't in the database yet. Only users an admin has added beforehand can log in. The option defaults to true, so existing deployments behave as before.An admin can add users ahead of their first login with any of:
rustguac add-user --email <email> --role <role> [--name <name>]POST /api/users(admin only), returns 201, or 409 if the user existsA user added this way keeps the role the admin gave them; default_role is not applied. Group-to-role mappings still apply on every login.
A rejected SSO login now redirects to the login page with an error code instead of returning JSON. This covers a user with no account (sso_error=no_account) and a disabled account (sso_error=disabled). SSO errors are now shown under the SSO button: they used to go into the API key form, which is hidden when SSO is on, so "SSO login failed" was never visible. The "provider unavailable" notice uses the same element, and all SSO messages are defined in one place in index.html.