diff --git a/src/views/DocumentationV6View.vue b/src/views/DocumentationV6View.vue
index 82f6dff..5026370 100644
--- a/src/views/DocumentationV6View.vue
+++ b/src/views/DocumentationV6View.vue
@@ -892,6 +892,12 @@ const mobileNavOpen = ref(false);
description="Group name that grants read-only access (e.g., 'kellnr-readonly')." />
+
+
Toolchain Server
@@ -954,6 +960,8 @@ const mobileNavOpen = ref(false);
Automatic user provisioning on first login
Group-based admin and read-only role assignment
Customizable login button text
+ Optional SSO-only mode that disables password login entirely
+ RP-initiated logout, ending the session at the identity provider as well
@@ -1041,6 +1049,88 @@ const mobileNavOpen = ref(false);
read_only_group_value = "kellnr-readonly"
+
+ SSO-Only Login
+ By default, the SSO button sits next to the username and password form, so both login methods stay
+ available. Set enforced to make SSO the only way in:
+
+
+
+ [oauth2]
+ enabled = true
+ enforced = true
+
+
+
+ With enforcement on, Kellnr rejects every path that relies on a local password:
+
+ - The login endpoint refuses username and password credentials
+ - Changing your own password and resetting another user's password are refused
+ - Creating a local user is refused, since users come from the identity provider
+ - HTTP Basic authentication against the registry API is refused
+
+ The web UI hides the matching forms and buttons, so the password form, the Change Password tab, the
+ Add User form and the password reset action disappear.
+
+ Cargo API tokens are unaffected. They are independent of how a user logs in, so
+ cargo publish and cargo add keep working exactly as before.
+
+
+
+ Configure admin_group_claim and admin_group_value before enabling enforced on a
+ fresh instance. The local admin account can no longer log in, and without a group mapping no user
+ provisioned through SSO is ever promoted, which leaves the instance without an administrator. Kellnr
+ logs a warning at startup when it detects this combination.
+
+
+
+ Kellnr also refuses to start when enforced is set but the OIDC handler cannot be initialized,
+ for example because the provider is unreachable or the issuer URL is malformed. Starting anyway would
+ serve a registry that nobody can log into, so the process exits with status code 1 and logs the reason
+ instead.
+
+
+
+ Skipping the Login Page
+ Once SSO is the only login method, the login page holds a single button. Set auto_redirect to
+ send users straight to the identity provider instead:
+
+
+
+ [oauth2]
+ enabled = true
+ enforced = true
+ auto_redirect = true
+
+
+
+ auto_redirect requires enforced, and enforced requires enabled. Kellnr
+ rejects a configuration that sets one without the other, rather than silently disabling all login.
+
+
+
+ Logout
+ When your provider advertises an end_session_endpoint in its discovery document (RP-Initiated
+ Logout 1.0), logging out of Kellnr also ends the session at the provider. Kellnr redirects the browser
+ to that endpoint with the ID token as id_token_hint, and the provider redirects back to Kellnr
+ afterwards. Add your Kellnr URL to the provider's list of allowed post-logout redirect URIs, otherwise
+ the provider refuses the redirect:
+
+ - https://your-kellnr-host/
+ - https://your-kellnr-host/your-prefix/ when origin.path is set
+
+ Providers without an end_session_endpoint only have the local Kellnr session cleared, so the
+ provider may sign the user straight back in on the next login attempt.
+
+
+
+ Kellnr keeps the ID token in a cookie to pass it back as id_token_hint. Browsers cap a single
+ cookie at roughly 4 KB, so a very large ID token, typically one carrying many group memberships, is
+ dropped and the provider session is no longer ended on logout. The local Kellnr session is still
+ cleared, so the only visible symptom is that the provider signs the user straight back in. If you hit
+ this, trim the claims your provider puts in the ID token.
+
+
The client secret should be kept confidential. It is recommended to set it via the
KELLNR_OAUTH2__CLIENT_SECRET environment variable rather than storing it in the config file.
@@ -1474,6 +1564,16 @@ const mobileNavOpen = ref(false);
Enable OAuth2/OIDC authentication |
false |
+
+ --oauth2-enforced |
+ Make SSO the only way to log in |
+ false |
+
+
+ --oauth2-auto-redirect |
+ Skip the login page and redirect to the identity provider |
+ false |
+