feat(auth): add Owner authentication source settings
Manage Yggdrasil providers from the panel using durable platform settings, protected identity namespaces and atomic revisions. Apply changes to subsequent logins and profile lookups without restarting. Return operator-host logouts to the login method selection page.
This commit is contained in:
33 files changed
+1466
-18
No files matched your search
@@ -59,11 +59,11 @@ type Config struct {
|
||||
// the tag, which cannot know that "littleskin" is meant to read LS.
|
||||
// No trusted/identity field, by design — see Config.AuthSources.
|
||||
type AuthSourceConfig struct {
|
||||
Tag string `toml:"tag"`
|
||||
Prefix string `toml:"prefix"`
|
||||
URL string `toml:"url"`
|
||||
Tag string `toml:"tag" json:"tag"`
|
||||
Prefix string `toml:"prefix" json:"prefix"`
|
||||
URL string `toml:"url" json:"url"`
|
||||
// APIURL is optional for sources whose hasJoined URL does not use the standard path.
|
||||
APIURL string `toml:"api_url"`
|
||||
APIURL string `toml:"api_url" json:"api_url"`
|
||||
}
|
||||
|
||||
// SMTPConfig is the [smtp] table: the outbound mail relay felis-api delivers
|
||||
@@ -672,6 +672,12 @@ func (o OffsiteConfig) validate() error {
|
||||
// leave a legible name behind after truncation.
|
||||
var authSourcePrefixRe = regexp.MustCompile(`^[A-Za-z0-9]{1,4}$`)
|
||||
|
||||
// ValidateAuthSources applies the same identity and endpoint rules to panel and
|
||||
// TOML configuration. Mojang remains the code-owned first source.
|
||||
func ValidateAuthSources(sources []AuthSourceConfig) error {
|
||||
return (&Config{AuthSources: sources}).validateAuthSources()
|
||||
}
|
||||
|
||||
// validateAuthSources checks the [[auth_source]] block: each needs a namespace tag, a rename
|
||||
// prefix, and a scheme-qualified hasJoined URL, and both tag and prefix must be unique. A
|
||||
// blank, duplicate or colon-bearing tag collapses two sources into one UUID namespace
|
||||
|
||||
Reference in new issue
Block a user