feat: SSO group autocomplete for per-host SSO allow-lists (v1.34.0)
The per-host "Allowed groups" field suggested only local groups, permission subjects and conf.auth maps. None of those can ever match an SSO-gated host: its allow-list is checked against the `groups` claim the SSO issues (utils/host_sso.js), so only SSO groups are candidates. Adds a conf.sso block (url + read-only apiToken, minted by theta-suite's bootstrap) and a cached /api/group lookup merged into the suggestions. Degrades silently to the previous local-only list when unset, and never fails the request. Authenticates with `Authorization: Bearer <token>` -- the SSO's `auth-token` header is for browser session UUIDs and rejects a minted API token. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -45,6 +45,18 @@ module.exports = {
|
||||
usernameClaim: 'preferred_username',
|
||||
},
|
||||
|
||||
// Read-only SSO management API access, used to populate the per-host SSO
|
||||
// allow-list autocomplete with the groups that actually exist in the
|
||||
// directory. Without it the "Allowed groups" field can only suggest groups
|
||||
// the proxy already knows locally, which for an SSO-gated host is usually
|
||||
// none of the ones the operator wants. `apiToken` is a machine token minted
|
||||
// by the theta-suite bootstrap and lives in secrets.js; leaving it unset
|
||||
// simply falls back to the local-only suggestions.
|
||||
sso: {
|
||||
url: '', // e.g. https://sso.example.com
|
||||
apiToken: '',
|
||||
},
|
||||
|
||||
// Authorization: how groups map to roles, and which groups are global admin.
|
||||
// Per-user overrides are Grant records managed in the app.
|
||||
auth: {
|
||||
|
||||
Reference in New Issue
Block a user