feat(oidc): rename the auth source Gitborg Auth -> Bitborg Auth #383
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!383
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/rename-oidc-source-name"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Step C of the OIDC auth-source rename
Gitborg Auth→Bitborg Auth— the last user-visiblegitborgstring on the service, since the source name is also the login-button label and thecallback slug
/user/oauth2/<name>/callback.What this changes
forgejo_oidc_source_name→Bitborg Auth. Kanidm's callback + landing URL and Caddy's@forgejo_login_pageredirect all derive from it, so they move with it.forgejoclient, returning it to a singleorigin_urlsentry.GF_AUTH_GENERIC_OAUTH_NAME— a separate hardcoded literal that does not derivefrom the variable, so the Forgejo rename alone would have left Grafana's sign-in page reading the
old name.
zero-gap procedure, and corrects two notes that have since gone stale.
Why it is sequenced
The name lives in two systems at once, so whichever side moves first breaks logins: rename Forgejo
and it posts a callback Kanidm has not registered; move Kanidm and it stops accepting the callback
Forgejo still posts. Order used: register both callbacks and apply
kanidm→ rename the live sourcein place and restart Forgejo → this PR.
No secret rotation.
login_source.idis unchanged and users link to a source by ID, not by name, soexisting OIDC links survive untouched.
Two findings worth recording
The canonical sign-in URL was serving 500 between steps B and C.
GET /user/login→ 302 to theold slug → 500. Step B had verified
/user/oauth2/<new name>— the route it changed — but not theCaddy redirect a user actually traverses. No blackbox probe covers
/user/login, so all six probesreported
1throughout. This PR is the fix.--checkcannot prove the add-source guard is safe.List existing Forgejo auth sourcesis acommand, so it is skipped under--check; the guard then evaluates<name> not in ''(true), andthe add-source task reports
skippingregardless because it is also acommand. The valid proof isa differential against the live host:
/user/oauth2/Bitborg%20Auth/user/oauth2/Gitborg%20Auth/user/oauth2/Definitely%20Not%20A%20SourceThe old name behaving identically to a name that was never registered is what establishes that
exactly one source exists and it carries the new name — so the real-run guard evaluates false and
cannot duplicate.
Dry-run
site.yml --check --diff: prodchanged=5 failed=0, monitoringchanged=2 failed=0. The five arethe kanidm provisioning state, the
app.inirender + itsflush_handlers, and the Caddyfile rendergrafana.container+ its restart. Expect brief Forgejo, Caddy andGrafana restarts.
ansible-lintwas not run in this session (blocked locally);--syntax-check,markdownlintandprettierall pass.Verification after apply
Plus a real browser sign-in, which is the only end-to-end proof.
The last user-visible `gitborg` string on the service: the source name is also the login-button label ("Sign in with <name>") and the callback slug (/user/oauth2/<name>/callback). Renamed with NO login gap, in three steps, because the name lives in two systems at once and whichever side moves first breaks logins — rename Forgejo and it posts a callback Kanidm has not registered; move Kanidm and it stops accepting the callback Forgejo still posts: A. register BOTH callbacks on the Kanidm forgejo client, apply kanidm only B. rename the live source IN PLACE (`admin auth update-oauth --id 2 --name`) and restart Forgejo — the in-memory OIDC provider does not pick the name up otherwise, the same way it does not pick up a changed secret C. move forgejo_oidc_source_name, drop the transitional callback, apply This commit is step C. No secret rotation, contrary to the plan's "the origin, the source name and the client secret must move together". `login_source.id` is unchanged and users link to a source by ID, not by name, so existing OIDC links survive untouched. That coupling only exists if the source is deleted and re-added — which `auth delete` refuses anyway for a source with linked users. Ansible only ADDS a source whose name is absent, so the variable change and the live rename must land together: a changed variable against an unchanged server produces a SECOND source rather than a rename. Two things step C turned out to be load-bearing for, neither of which was anticipated: * Caddy's @forgejo_login_page redirect derives from the same variable, so between B and C the canonical https://git.bitborg.se/user/login served a 302 to the OLD slug and then a 500. Step B had verified /user/oauth2/<new name> directly — the route it had just changed — but not the redirect a user actually traverses. No blackbox probe covers /user/login, so all six kept reporting 1 throughout. Step C is the fix. * The dry-run CANNOT prove the add-source guard is safe, so the reference check-run's "the add-source task is absent from the changed list" was not evidence. `List existing Forgejo auth sources` is a `command`, skipped under --check, so the guard evaluates `<name> not in ''` — true — and the add-source task then reports `skipping` whether the guard passed or failed, because it is also a `command`. The real proof is a differential against production: the new name 307s to Kanidm while the old name AND a deliberately bogus name both 500 identically, which establishes that exactly one source exists and it carries the new name. Also renames Grafana's GF_AUTH_GENERIC_OAUTH_NAME, which is a SEPARATE hardcoded literal and does not derive from forgejo_oidc_source_name — renaming the Forgejo source alone would have left Grafana's sign-in page still reading "Gitborg Auth". Same class of miss as the hardcoded KANIDM_HOST and the Forgejo footer link text. Its whole KEY=value stays double-quoted, because systemd Environment= splits unquoted values on whitespace and the value contains a space. Runbook: records the rename, replaces the old "two-source cleanup" note with the sequenced zero-gap procedure that was actually proven, and drops the claim that the secret must move with the name. Corrects two notes that were true when written and are not now: `fj pr create` works again on 0.6.0 (the browser workaround is unnecessary), and the second fj credential store does NOT hold a separate server-side token — all three key files held the same value, so revoking it as advised would have broken the working CLI.