kanidm: ask upstream for a configurable link on the sign-in page #337

Öppen
öppnade 2026-08-02 12:30:49 +00:00 av supernaut · 0 kommentarer
Ägare

Kanidm offers no way to add a link to its sign-in page. Deployments where account creation happens
outside Kanidm therefore strand a visitor who has no account: the page can prompt for a username
and offer account recovery, and nothing else.

The existing upstream requests do not cover this:

Ours is much smaller and sits between the two: let the operator configure one link — a label and
a URL — rendered on the sign-in page. The template already has exactly this pattern for account
recovery (server/core/templates/login.html, gated on
display_ctx.domain_info.allow_account_recovery()), and the domain entry already carries operator
settings of this shape (set-displayname, set-image, set-allow-account-recovery).

Scope

  • Open an issue on kanidm/kanidm proposing an operator-settable sign-in link (label + URL),
    framed as complementing rather than pre-empting the self-registration request.
  • Link it from this issue and from the CSS comment that documents the workaround.
  • If accepted and released, retire the CSS note and the health-gate entry that guards it.

Part of gitborg/gitborg-docs#69.

Kanidm offers no way to add a link to its sign-in page. Deployments where account creation happens outside Kanidm therefore strand a visitor who has no account: the page can prompt for a username and offer account recovery, and nothing else. The existing upstream requests do not cover this: - <https://github.com/kanidm/kanidm/issues/1996> ("Admin-configurable theming") asked for a custom logo *and accompanying text*; it closed with display name + image + `override.css` only. - <https://github.com/kanidm/kanidm/issues/2287> ("FR: User sign-up portal") asks for full self-registration inside Kanidm and has been open since 2023. Ours is much smaller and sits between the two: let the operator configure **one** link — a label and a URL — rendered on the sign-in page. The template already has exactly this pattern for account recovery (`server/core/templates/login.html`, gated on `display_ctx.domain_info.allow_account_recovery()`), and the domain entry already carries operator settings of this shape (`set-displayname`, `set-image`, `set-allow-account-recovery`). ## Scope - [ ] Open an issue on `kanidm/kanidm` proposing an operator-settable sign-in link (label + URL), framed as complementing rather than pre-empting the self-registration request. - [ ] Link it from this issue and from the CSS comment that documents the workaround. - [ ] If accepted and released, retire the CSS note and the health-gate entry that guards it. Part of gitborg/gitborg-docs#69.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#337
Ingen beskrivning angiven.