Fix #371: OIDC anonymous read + navbar identity #375
No reviewers
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub!375
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/issue-371"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes #371 (anonymous read in OIDC mode + navbar Login/identity dropdown).
A. Validation flip (oidc + anonymous_read=true allowed)
internal/config/validate.go: removed the blanketanonymous_read must be false in oidc moderefusal. true = default recommendation (visitors browse public repos per #345 visibility semantics, navbar offers Login); false = everything-requires-login hard-lock. Allowlist + oauth pair + #344 browser-login trio + secret-length rules unchanged.web/src/lib/setup.js: setup copy rewritten (field note + removed client mirror of the ban);/api/v1/setup/testagrees via config.Validate./_auth/logoutclear-cookie + sanitized-next 302 contract — no code change, it already exists); 07_api.md §8 + §14.B. Navbar identity surface
GET /api/v1/megainsadmin; discovery auth block gainsmode(none|token|oidc). Both ride already-fetched payloads (sharedmekey, one AuthOpen discovery GET per app load) — zero new hot-path trips./_auth/meuntouched (edge contract).web/src/lib/identity.js(new, pure): navModel matrix — signed-out + browser_login → Login (/_auth/login?next=<current>); signed-in (non-anon, mode != none) → identity menu (profile /{username}, keys, invitations, setup iff admin, logout →/_auth/logout?next=/); none mode → today's nav, no Login, no menu; login hidden when the flow is disabled.web/src/components/IdentityMenu.jsx(new): avatar-or-username button (optional avatarUrl prop stages #349), #255/#311 popover contract (outside-click, Esc + focus return, arrows, menu/menuitem roles), logout as plain anchor, username truncates for 390px.App.jsx: keys/invitations/setup leave the primary nav for signed-in users (setup stays in nav in none mode); identity control left of the tray.Tests