Phase 4: real OIDC human login (enterprise/internal/loginhandler)
Closes the other major named gap from this phase: until now, there was no way for a human to actually log in -- only /alerting's RoleService credential could be minted. GET /auth/oidc/login and GET /auth/oidc/callback drive the real coreos/go-oidc flow already wired in enterprise/internal/oidc: CSRF state in a short-lived cookie, code exchange, ID token verification, upserting a users row, resolving tenant/role from exactly one tenant_memberships row (refusing outright on zero or more than one, rather than guessing), and issuing a real session cookie. Unlike everything else built this phase, this one is genuinely verified end to end: the tests spin up coreos/go-oidc's own oidctest fake IdP, which signs real RS256 ID tokens, and drive the full login->callback-> session-cookie round trip through actual signature verification -- no live database or Docker needed, so nothing here is asserted without having actually been run in this session. Also fixes a real bug caught while wiring this into enterprise-auth's main.go: assigning a nil *oidc.Provider to the handler's interface field would have produced a non-nil interface wrapping a nil pointer (Go's classic typed-nil trap), silently breaking the "OIDC not configured" no-op path -- New() now takes the concrete pointer type and checks it before ever converting to the interface, with a regression test pinning the fix down. Still missing: SAML's equivalent (ACS endpoint), a tenant-picker UI for multi-membership identities, and any admin UI to actually create a tenant_memberships row (today that's manual SQL, documented in the runbook's new bootstrap walkthrough).
This commit is contained in:
@@ -13,6 +13,10 @@ type Config struct {
|
||||
OIDC OIDCConfig
|
||||
SAML SAMLConfig
|
||||
SessionSigningKey []byte
|
||||
// PostLoginRedirectURL is where the browser lands after
|
||||
// internal/loginhandler sets a session cookie -- web's base URL in
|
||||
// a real deployment.
|
||||
PostLoginRedirectURL string
|
||||
}
|
||||
|
||||
type PostgresConfig struct {
|
||||
@@ -66,6 +70,7 @@ func Load() (Config, error) {
|
||||
ACSURL: getenv("SAML_ACS_URL", ""),
|
||||
IDPMetadataURL: getenv("SAML_IDP_METADATA_URL", ""),
|
||||
},
|
||||
PostLoginRedirectURL: getenv("POST_LOGIN_REDIRECT_URL", "http://localhost:3000"),
|
||||
}
|
||||
|
||||
// Required, unlike OIDC/SAML above: every enterprise-auth deployment
|
||||
|
||||
Reference in New Issue
Block a user