Fix #344: OIDC browser login #352

Merged
crueber merged 2 commits from fix/issue-344 into main 2026-09-11 22:58:07 +00:00
Owner

Fixes #344 — OIDC browser login was dead (bare 401, /_auth/login 501, silent misconfig boot).

WHAT: (1) config.Validate refuses auth.mode=oidc without the full browser-login trio (session_secret/oauth_client_id/oauth_client_secret), naming missing keys — refuse-to-start per law 9, chosen over a degraded boot (a serving-degraded mode would need its own gate semantics; #345 owns signed-out readability). (2) unauthenticated browser GETs get a usable entry: 307 to the provider when enabled; 401 carrying the rendered 'Log in with OIDC' page (working button + disabled explanation + config-check//setup pointers) when not. /_auth/login renders the same page (501) for browsers; API clients keep plain statuses. (3) browser_login/login_url advertised in discovery auth block and setup.json; setup.js fails per missing trio key before save. (4) /_auth/login signs next into state (hostile targets sanitize to /); static tokens still authenticate in oidc mode.

COHERENCE WITH #345: shared gate chain (Env.gate, smart.go, lfs.go, shell gated()) untouched except the login path; fix holds under current semantics (anonymous_read=false still gates), #345 can layer visibility-as-authority on top.

TESTS (-race): config trio-missing x3 + all-missing + non-oidc exempt; server decision table (enabled 307 / disabled 401+page / plain 401 / credentialed no-redirect / enabled non-browser 401), login 501 page vs plain, next roundtrip incl. hostile, static-token-in-oidc, setup.json advertisement; api discovery table x5; node --test setup-oidc-trio (6) + updated setup-form fixtures. Coverage: config 95.7%, api 95.4%, server 98.5%. gofmt/vet clean. Existing fixtures updated to the intended rule (validate_test base, setup_merge_test trio, setup-form oidc bases).

DEVIATIONS/ENV NOTES: web/test/unit/smoke.test.js 2 failures are environmental — a foreign live 'walhub serve' occupies 127.0.0.1:8080 in this workspace (untouched per instructions); with no server present those tests skip cleanly. Full web suite otherwise 662/664 (2 = the smoke pair).

Fixes #344 — OIDC browser login was dead (bare 401, /_auth/login 501, silent misconfig boot). WHAT: (1) config.Validate refuses auth.mode=oidc without the full browser-login trio (session_secret/oauth_client_id/oauth_client_secret), naming missing keys — refuse-to-start per law 9, chosen over a degraded boot (a serving-degraded mode would need its own gate semantics; #345 owns signed-out readability). (2) unauthenticated browser GETs get a usable entry: 307 to the provider when enabled; 401 carrying the rendered 'Log in with OIDC' page (working button + disabled explanation + config-check//setup pointers) when not. /_auth/login renders the same page (501) for browsers; API clients keep plain statuses. (3) browser_login/login_url advertised in discovery auth block and setup.json; setup.js fails per missing trio key before save. (4) /_auth/login signs next into state (hostile targets sanitize to /); static tokens still authenticate in oidc mode. COHERENCE WITH #345: shared gate chain (Env.gate, smart.go, lfs.go, shell gated()) untouched except the login path; fix holds under current semantics (anonymous_read=false still gates), #345 can layer visibility-as-authority on top. TESTS (-race): config trio-missing x3 + all-missing + non-oidc exempt; server decision table (enabled 307 / disabled 401+page / plain 401 / credentialed no-redirect / enabled non-browser 401), login 501 page vs plain, next roundtrip incl. hostile, static-token-in-oidc, setup.json advertisement; api discovery table x5; node --test setup-oidc-trio (6) + updated setup-form fixtures. Coverage: config 95.7%, api 95.4%, server 98.5%. gofmt/vet clean. Existing fixtures updated to the intended rule (validate_test base, setup_merge_test trio, setup-form oidc bases). DEVIATIONS/ENV NOTES: web/test/unit/smoke.test.js 2 failures are environmental — a foreign live 'walhub serve' occupies 127.0.0.1:8080 in this workspace (untouched per instructions); with no server present those tests skip cleanly. Full web suite otherwise 662/664 (2 = the smoke pair).
config.Validate refuses auth.mode=oidc without the browser-login trio
(session_secret/oauth_client_id/oauth_client_secret), naming the missing
keys (11_config_cli.md rule 2). Gated-group 401s for browser-ish GETs now
carry the rendered Log in with OIDC page instead of a bare string, and
/_auth/login renders it (501) for browsers; API clients keep plain
statuses (06_server_http.md 2.2 #8 + Decisions). browser_login/login_url
advertised in discovery auth block and setup.json; setup.js warns per-key
before save. Bearer/token paths untouched.
Sign in to join this conversation.
No description provided.