sign-in: offer account creation to visitors who have none #336

Stängd
öppnade 2026-08-02 12:30:48 +00:00 av supernaut · 0 kommentarer
Ägare

A visitor who clicks "Sign In" on the Forgejo app is redirected straight into the identity
provider's username prompt. Local registration is disabled (the portal is the only sign-up path),
so a person without an account reaches a form they cannot complete and is offered nothing else —
no "create an account", no way back to the portal.

Kanidm has no configuration for this. Its documented customisation surface is the site display
name, the site image, per-application display names and images, and a custom stylesheet at
/hpkg/override.css — nothing that can inject a link, and CSS content: cannot produce a
clickable anchor. See https://kanidm.github.io/kanidm/stable/customising.html. Verified against
the deployed 1.10.4 and against upstream master; the same conclusion is already recorded in
roles/kanidm/templates/override.css.j2 and in the OAuth2 client declaration.

So fix it where we do have a supported hook.

Scope

  1. Forgejo navbar link (the actual fix). Add a custom/extra_links.tmpl hook rendering a
    "Create account" link to https://www.gitborg.se/signup, alongside the existing
    header.tmpl / extra_links_footer.tmpl hooks in roles/forgejo/templates/custom/. Gate it on
    the visitor being signed out. Plain HTML, matching the footer hook's style.

  2. A note on the identity provider's sign-in page (signposting). Add a rule to
    roles/kanidm/templates/override.css.j2 appending a short line — "No account yet? Create one at
    www.gitborg.se/signup" — scoped to the username step only. input#username[name="username"]
    appears on login.html and on no other login-step template at 1.10.4, so
    form#login:has(input#username[name="username"])::after is a precise selector.

    State in the comment that this is text, not a link: CSS cannot create an anchor, and
    generated content is not user-selectable in Chromium or WebKit, so keep the URL short enough to
    retype. English only — CSS content cannot vary by language.

  3. Guard the selector. Extend the concealment health gate in
    roles/health-check/tasks/main.yml so its verification list includes
    https://auth.gitborg.se/ui/login → the sign-up note is present. A CSS rule that no-ops after an
    upgrade fails silently; the gate is what makes that visible.

Out of scope

Rewriting the identity provider's response body at the proxy to inject a real anchor. It is
technically viable (the sign-in page is server-rendered HTML, the auth vhost is uncompressed, and
CSP does not restrict anchors) but it means adding a pre-1.0 third-party body-rewriting module to
the TLS-terminating edge for a cosmetic gain. Reconsider only if measured drop-off justifies it.

Done when

  • A signed-out visitor on the Forgejo app sees a "Create account" link that reaches the portal
    sign-up page.
  • The identity provider's sign-in page shows the sign-up note; no other login step does.
  • The health gate lists the sign-in page among the surfaces to re-verify on an image bump.
  • Runbook/docs note that the sign-in note is text-only and why.

Part of gitborg/gitborg-docs#69.

A visitor who clicks "Sign In" on the Forgejo app is redirected straight into the identity provider's username prompt. Local registration is disabled (the portal is the only sign-up path), so a person without an account reaches a form they cannot complete and is offered nothing else — no "create an account", no way back to the portal. Kanidm has no configuration for this. Its documented customisation surface is the site display name, the site image, per-application display names and images, and a custom stylesheet at `/hpkg/override.css` — nothing that can inject a link, and CSS `content:` cannot produce a clickable anchor. See <https://kanidm.github.io/kanidm/stable/customising.html>. Verified against the deployed 1.10.4 and against upstream `master`; the same conclusion is already recorded in `roles/kanidm/templates/override.css.j2` and in the OAuth2 client declaration. So fix it where we *do* have a supported hook. ## Scope 1. **Forgejo navbar link (the actual fix).** Add a `custom/extra_links.tmpl` hook rendering a "Create account" link to `https://www.gitborg.se/signup`, alongside the existing `header.tmpl` / `extra_links_footer.tmpl` hooks in `roles/forgejo/templates/custom/`. Gate it on the visitor being signed out. Plain HTML, matching the footer hook's style. 2. **A note on the identity provider's sign-in page (signposting).** Add a rule to `roles/kanidm/templates/override.css.j2` appending a short line — "No account yet? Create one at www.gitborg.se/signup" — scoped to the username step only. `input#username[name="username"]` appears on `login.html` and on no other login-step template at 1.10.4, so `form#login:has(input#username[name="username"])::after` is a precise selector. State in the comment that this is **text, not a link**: CSS cannot create an anchor, and generated content is not user-selectable in Chromium or WebKit, so keep the URL short enough to retype. English only — CSS `content` cannot vary by language. 3. **Guard the selector.** Extend the concealment health gate in `roles/health-check/tasks/main.yml` so its verification list includes `https://auth.gitborg.se/ui/login → the sign-up note is present`. A CSS rule that no-ops after an upgrade fails silently; the gate is what makes that visible. ## Out of scope Rewriting the identity provider's response body at the proxy to inject a real anchor. It is technically viable (the sign-in page is server-rendered HTML, the auth vhost is uncompressed, and CSP does not restrict anchors) but it means adding a pre-1.0 third-party body-rewriting module to the TLS-terminating edge for a cosmetic gain. Reconsider only if measured drop-off justifies it. ## Done when - [ ] A signed-out visitor on the Forgejo app sees a "Create account" link that reaches the portal sign-up page. - [ ] The identity provider's sign-in page shows the sign-up note; no other login step does. - [ ] The health gate lists the sign-in page among the surfaces to re-verify on an image bump. - [ ] Runbook/docs note that the sign-in note is text-only and why. Part of gitborg/gitborg-docs#69.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#336
Ingen beskrivning angiven.