diff --git a/src/views/DocumentationV6View.vue b/src/views/DocumentationV6View.vue index 82f6dff..5026370 100644 --- a/src/views/DocumentationV6View.vue +++ b/src/views/DocumentationV6View.vue @@ -892,6 +892,12 @@ const mobileNavOpen = ref(false); description="Group name that grants read-only access (e.g., 'kellnr-readonly')." /> + + Toolchain Server @@ -954,6 +960,8 @@ const mobileNavOpen = ref(false);
  • Automatic user provisioning on first login
  • Group-based admin and read-only role assignment
  • Customizable login button text
  • +
  • Optional SSO-only mode that disables password login entirely
  • +
  • RP-initiated logout, ending the session at the identity provider as well
  • @@ -1041,6 +1049,88 @@ const mobileNavOpen = ref(false); read_only_group_value = "kellnr-readonly" + + SSO-Only Login
    + By default, the SSO button sits next to the username and password form, so both login methods stay + available. Set enforced to make SSO the only way in: +
    + + + [oauth2] + enabled = true + enforced = true + + + + With enforcement on, Kellnr rejects every path that relies on a local password: +
      +
    • The login endpoint refuses username and password credentials
    • +
    • Changing your own password and resetting another user's password are refused
    • +
    • Creating a local user is refused, since users come from the identity provider
    • +
    • HTTP Basic authentication against the registry API is refused
    • +
    + The web UI hides the matching forms and buttons, so the password form, the Change Password tab, the + Add User form and the password reset action disappear.
    +
    + Cargo API tokens are unaffected. They are independent of how a user logs in, so + cargo publish and cargo add keep working exactly as before. +
    + + + Configure admin_group_claim and admin_group_value before enabling enforced on a + fresh instance. The local admin account can no longer log in, and without a group mapping no user + provisioned through SSO is ever promoted, which leaves the instance without an administrator. Kellnr + logs a warning at startup when it detects this combination. + + + + Kellnr also refuses to start when enforced is set but the OIDC handler cannot be initialized, + for example because the provider is unreachable or the issuer URL is malformed. Starting anyway would + serve a registry that nobody can log into, so the process exits with status code 1 and logs the reason + instead. + + + + Skipping the Login Page
    + Once SSO is the only login method, the login page holds a single button. Set auto_redirect to + send users straight to the identity provider instead: +
    + + + [oauth2] + enabled = true + enforced = true + auto_redirect = true + + + + auto_redirect requires enforced, and enforced requires enabled. Kellnr + rejects a configuration that sets one without the other, rather than silently disabling all login. + + + + Logout
    + When your provider advertises an end_session_endpoint in its discovery document (RP-Initiated + Logout 1.0), logging out of Kellnr also ends the session at the provider. Kellnr redirects the browser + to that endpoint with the ID token as id_token_hint, and the provider redirects back to Kellnr + afterwards. Add your Kellnr URL to the provider's list of allowed post-logout redirect URIs, otherwise + the provider refuses the redirect: +
      +
    • https://your-kellnr-host/
    • +
    • https://your-kellnr-host/your-prefix/ when origin.path is set
    • +
    + Providers without an end_session_endpoint only have the local Kellnr session cleared, so the + provider may sign the user straight back in on the next login attempt. +
    + + + Kellnr keeps the ID token in a cookie to pass it back as id_token_hint. Browsers cap a single + cookie at roughly 4 KB, so a very large ID token, typically one carrying many group memberships, is + dropped and the provider session is no longer ended on logout. The local Kellnr session is still + cleared, so the only visible symptom is that the provider signs the user straight back in. If you hit + this, trim the claims your provider puts in the ID token. + + The client secret should be kept confidential. It is recommended to set it via the KELLNR_OAUTH2__CLIENT_SECRET environment variable rather than storing it in the config file. @@ -1474,6 +1564,16 @@ const mobileNavOpen = ref(false); Enable OAuth2/OIDC authentication false + + --oauth2-enforced + Make SSO the only way to log in + false + + + --oauth2-auto-redirect + Skip the login page and redirect to the identity provider + false +