hive-forge: a first authelia login creates the forge account
[oauth2_client] turns on auto-registration through the authelia login source, with the account named after authelia's preferred_username. DISABLE_REGISTRATION stays true: forgejo 16's auto-registration checks only ALLOW_ONLY_INTERNAL_REGISTRATION, so local sign-up stays off. ACCOUNT_LINKING is `login`, forgejo's default, set explicitly. With `auto`, an SSO login whose name matches an existing local account would be handed that account, and agents, `core` and `swarm-controller` all have one. `login` asks for that account's own password instead. Refs #3782
This commit is contained in:
parent
2cc3d62d5f
commit
113f3fe6e2
2 changed files with 49 additions and 3 deletions
|
|
@ -775,13 +775,33 @@ in
|
||||||
# the custom theme CSS baked straight into the nix store.
|
# the custom theme CSS baked straight into the nix store.
|
||||||
STATIC_ROOT_PATH = staticRootWithTheme;
|
STATIC_ROOT_PATH = staticRootWithTheme;
|
||||||
};
|
};
|
||||||
# Registration off — operator seeds agent users via
|
# Local sign-up off. An agent's account is made by
|
||||||
# `nixos-container run hive-forge -- forgejo admin
|
# swarm-controller over the admin API, a human's by their
|
||||||
# user create …`.
|
# first authelia login (`oauth2_client` below), which this
|
||||||
|
# does not block: forgejo's auto-registration checks only
|
||||||
|
# `ALLOW_ONLY_INTERNAL_REGISTRATION`
|
||||||
|
# (`routers/web/auth/oauth.go`, 16.0.5).
|
||||||
service = {
|
service = {
|
||||||
DISABLE_REGISTRATION = true;
|
DISABLE_REGISTRATION = true;
|
||||||
REQUIRE_SIGNIN_VIEW = false;
|
REQUIRE_SIGNIN_VIEW = false;
|
||||||
};
|
};
|
||||||
|
# A first login through the authelia source creates the
|
||||||
|
# account, named after authelia's `preferred_username` — the
|
||||||
|
# authelia username, not the opaque `sub`.
|
||||||
|
#
|
||||||
|
# ⚠️ `ACCOUNT_LINKING = login`, never `auto`. A login whose
|
||||||
|
# name is already taken does not create an account; `auto`
|
||||||
|
# would then hand the SSO user the existing one. Agents,
|
||||||
|
# `core` and `swarm-controller` all have local accounts here,
|
||||||
|
# the last two site admins, and `swarmctl user add` refuses
|
||||||
|
# none of those names. `login` asks for the existing
|
||||||
|
# account's own password instead, which an agent's or a
|
||||||
|
# service account's never leaves the forge.
|
||||||
|
oauth2_client = {
|
||||||
|
ENABLE_AUTO_REGISTRATION = true;
|
||||||
|
USERNAME = "preferred_username";
|
||||||
|
ACCOUNT_LINKING = "login";
|
||||||
|
};
|
||||||
repository = {
|
repository = {
|
||||||
DEFAULT_BRANCH = "main";
|
DEFAULT_BRANCH = "main";
|
||||||
DEFAULT_PRIVATE = "private";
|
DEFAULT_PRIVATE = "private";
|
||||||
|
|
|
||||||
|
|
@ -70,6 +70,8 @@ let
|
||||||
tokenFile = m: m.services.hyperhive.deploy.swarm-controller.forgeTokenFile;
|
tokenFile = m: m.services.hyperhive.deploy.swarm-controller.forgeTokenFile;
|
||||||
forgePath = "/var/lib/hyperhive-forge/swarm-controller.token";
|
forgePath = "/var/lib/hyperhive-forge/swarm-controller.token";
|
||||||
|
|
||||||
|
forgeSettings = forgeHere.containers.hive-forge.config.services.forgejo.settings;
|
||||||
|
|
||||||
cases = [
|
cases = [
|
||||||
{
|
{
|
||||||
# The absence the whole option exists for: a second forge in a swarm
|
# The absence the whole option exists for: a second forge in a swarm
|
||||||
|
|
@ -139,6 +141,30 @@ let
|
||||||
&& tokenFile forgeHere == forgePath
|
&& tokenFile forgeHere == forgePath
|
||||||
&& tokenFile allLocal == forgePath;
|
&& tokenFile allLocal == forgePath;
|
||||||
}
|
}
|
||||||
|
{
|
||||||
|
# The only thing that makes a human's forge account: nothing else
|
||||||
|
# creates one.
|
||||||
|
name = "a first authelia login creates the forge account, named by preferred_username";
|
||||||
|
ok =
|
||||||
|
let
|
||||||
|
o = forgeSettings.oauth2_client;
|
||||||
|
in
|
||||||
|
o.ENABLE_AUTO_REGISTRATION == true && o.USERNAME == "preferred_username";
|
||||||
|
}
|
||||||
|
{
|
||||||
|
# `auto` would give an SSO user whatever local account carries their
|
||||||
|
# name — an agent's, or `core`'s.
|
||||||
|
name = "an SSO login adopts an existing forge account only with that account's password";
|
||||||
|
ok = forgeSettings.oauth2_client.ACCOUNT_LINKING == "login";
|
||||||
|
}
|
||||||
|
{
|
||||||
|
# Both halves: local sign-up stays off, and nothing turns on the one
|
||||||
|
# setting forgejo's auto-registration does check.
|
||||||
|
name = "local sign-up stays off without blocking the SSO registration";
|
||||||
|
ok =
|
||||||
|
forgeSettings.service.DISABLE_REGISTRATION == true
|
||||||
|
&& !(forgeSettings.service.ALLOW_ONLY_INTERNAL_REGISTRATION or false);
|
||||||
|
}
|
||||||
];
|
];
|
||||||
in
|
in
|
||||||
runGroup "forge-placement" cases
|
runGroup "forge-placement" cases
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue