Control panel: bootstrap the bitborg-web Kanidm OAuth2 client + enable (follow-up to #47) #115

Stängd
öppnade 2026-07-18 20:31:31 +00:00 av supernaut · 0 kommentarer
Ägare

Operational follow-up to #47 — the runbook documented it; this provisions the client/secrets and enables the panel. Web code deployed (bitborg-web #57, JWKS verify + security review). Per runbook § Control-panel OAuth2 client:

  • Create the bitborg-web Kanidm OAuth2 client (redirect https://www.gitborg.se/auth/callback, PKCE on, scope-map forgejo_users openid profile email groups).
  • Vault vault_web_oidc_client_secret + vault_web_session_secret (sets web_auth_enabled).
  • site.yml --tags web + verify /account SSO login.

Done (applied by operator 2026-07-18). Verified live: /auth/login → 302 to auth.gitborg.se/ui/oauth2?...client_id=bitborg-web&redirect_uri=.../auth/callback&scope=openid+profile+email+groups&code_challenge_method=S256; /account (logged out) → 302 /auth/login?return_to=/account (was 404). Epic: gitborg/gitborg-docs#6.

Operational follow-up to #47 — the runbook documented it; this provisions the client/secrets and enables the panel. Web code deployed (bitborg-web #57, JWKS verify + security review). Per runbook § *Control-panel OAuth2 client*: - [x] Create the `bitborg-web` Kanidm OAuth2 client (redirect `https://www.gitborg.se/auth/callback`, PKCE on, scope-map `forgejo_users openid profile email groups`). - [x] Vault `vault_web_oidc_client_secret` + `vault_web_session_secret` (sets `web_auth_enabled`). - [x] `site.yml --tags web` + verify `/account` SSO login. **Done (applied by operator 2026-07-18).** Verified live: `/auth/login` → 302 to `auth.gitborg.se/ui/oauth2?...client_id=bitborg-web&redirect_uri=.../auth/callback&scope=openid+profile+email+groups&code_challenge_method=S256`; `/account` (logged out) → 302 `/auth/login?return_to=/account` (was 404). Epic: gitborg/gitborg-docs#6.
supernaut ändrade titeln från Control panel: bootstrap the gitborg-web Kanidm OAuth2 client + enable (follow-up to #47) till Control panel: bootstrap the bitborg-web Kanidm OAuth2 client + enable (follow-up to #47) 2026-08-03 09:58:42 +00:00
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#115
Ingen beskrivning angiven.