Fix #344: OIDC browser login #352
No reviewers
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub!352
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/issue-344"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes #344 — OIDC browser login was dead (bare 401, /_auth/login 501, silent misconfig boot).
WHAT: (1) config.Validate refuses auth.mode=oidc without the full browser-login trio (session_secret/oauth_client_id/oauth_client_secret), naming missing keys — refuse-to-start per law 9, chosen over a degraded boot (a serving-degraded mode would need its own gate semantics; #345 owns signed-out readability). (2) unauthenticated browser GETs get a usable entry: 307 to the provider when enabled; 401 carrying the rendered 'Log in with OIDC' page (working button + disabled explanation + config-check//setup pointers) when not. /_auth/login renders the same page (501) for browsers; API clients keep plain statuses. (3) browser_login/login_url advertised in discovery auth block and setup.json; setup.js fails per missing trio key before save. (4) /_auth/login signs next into state (hostile targets sanitize to /); static tokens still authenticate in oidc mode.
COHERENCE WITH #345: shared gate chain (Env.gate, smart.go, lfs.go, shell gated()) untouched except the login path; fix holds under current semantics (anonymous_read=false still gates), #345 can layer visibility-as-authority on top.
TESTS (-race): config trio-missing x3 + all-missing + non-oidc exempt; server decision table (enabled 307 / disabled 401+page / plain 401 / credentialed no-redirect / enabled non-browser 401), login 501 page vs plain, next roundtrip incl. hostile, static-token-in-oidc, setup.json advertisement; api discovery table x5; node --test setup-oidc-trio (6) + updated setup-form fixtures. Coverage: config 95.7%, api 95.4%, server 98.5%. gofmt/vet clean. Existing fixtures updated to the intended rule (validate_test base, setup_merge_test trio, setup-form oidc bases).
DEVIATIONS/ENV NOTES: web/test/unit/smoke.test.js 2 failures are environmental — a foreign live 'walhub serve' occupies 127.0.0.1:8080 in this workspace (untouched per instructions); with no server present those tests skip cleanly. Full web suite otherwise 662/664 (2 = the smoke pair).