sign-in: offer account creation to visitors who have none #336
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#336
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
A visitor who clicks "Sign In" on the Forgejo app is redirected straight into the identity
provider's username prompt. Local registration is disabled (the portal is the only sign-up path),
so a person without an account reaches a form they cannot complete and is offered nothing else —
no "create an account", no way back to the portal.
Kanidm has no configuration for this. Its documented customisation surface is the site display
name, the site image, per-application display names and images, and a custom stylesheet at
/hpkg/override.css— nothing that can inject a link, and CSScontent:cannot produce aclickable anchor. See https://kanidm.github.io/kanidm/stable/customising.html. Verified against
the deployed 1.10.4 and against upstream
master; the same conclusion is already recorded inroles/kanidm/templates/override.css.j2and in the OAuth2 client declaration.So fix it where we do have a supported hook.
Scope
Forgejo navbar link (the actual fix). Add a
custom/extra_links.tmplhook rendering a"Create account" link to
https://www.gitborg.se/signup, alongside the existingheader.tmpl/extra_links_footer.tmplhooks inroles/forgejo/templates/custom/. Gate it onthe visitor being signed out. Plain HTML, matching the footer hook's style.
A note on the identity provider's sign-in page (signposting). Add a rule to
roles/kanidm/templates/override.css.j2appending a short line — "No account yet? Create one atwww.gitborg.se/signup" — scoped to the username step only.
input#username[name="username"]appears on
login.htmland on no other login-step template at 1.10.4, soform#login:has(input#username[name="username"])::afteris a precise selector.State in the comment that this is text, not a link: CSS cannot create an anchor, and
generated content is not user-selectable in Chromium or WebKit, so keep the URL short enough to
retype. English only — CSS
contentcannot vary by language.Guard the selector. Extend the concealment health gate in
roles/health-check/tasks/main.ymlso its verification list includeshttps://auth.gitborg.se/ui/login → the sign-up note is present. A CSS rule that no-ops after anupgrade fails silently; the gate is what makes that visible.
Out of scope
Rewriting the identity provider's response body at the proxy to inject a real anchor. It is
technically viable (the sign-in page is server-rendered HTML, the auth vhost is uncompressed, and
CSP does not restrict anchors) but it means adding a pre-1.0 third-party body-rewriting module to
the TLS-terminating edge for a cosmetic gain. Reconsider only if measured drop-off justifies it.
Done when
sign-up page.
Part of gitborg/gitborg-docs#69.
supernaut refererade till detta ärende från bitborg/bitborg-docs2026-08-02 12:32:47 +00:00