feat(auth): register Tribelt as an OIDC client - #75
Merged
Merged
Conversation
The Tribelt mirror at tribelt.jorisjonkers.dev signs its /stats viewers in against this authorization server. Adds the registered client, a TRIBELT service permission, and the client_id -> permission mapping that gates the authorize endpoint -- the Outline/NOTES shape. The client is confidential (client_secret_basic and client_secret_post) and also requires PKCE. Redirect is /auth/callback, post-logout redirect is the site root; .test variants mirror every other downstream client. The secret comes from auth.clients.tribelt.secret, defaulting to tribelt-secret for local runs and tests exactly like the other clients. TRIBELT is enforced here rather than by forward-auth: the public site route is anonymous, so a forward-auth middleware would never run. DOWNSTREAM_CLIENT_PERMISSIONS moves the check to the authorize endpoint; ADMIN passes as usual. The ID token already carries a roles claim (ROLE_<role> plus SERVICE_<permission> per grant, every SERVICE_* for ADMIN), so the app can double-check SERVICE_TRIBELT after the gate. Userinfo uses the default mapper and returns only standard scope claims, not roles. No migration: user_service_permissions.service is VARCHAR(50) with no check constraint, and the OpenAPI spec does not enumerate permissions.
Adding the tribelt secret pushed AuthorizationServerConfig's constructor past detekt's LongParameterList limit of six.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Registers
tribeltas a confidential OIDC client that also requires PKCE, for the student test site at tribelt.jorisjonkers.dev and its/statsdashboard.ServicePermission.TRIBELT("tribelt").buildTribeltClient(): authorization_code + refresh_token, client_secret_basic/post, PKCE required, no consent, default token settings, scopesopenid profile email, redirecthttps://tribelt.jorisjonkers.dev/auth/callback, post-logout redirecthttps://tribelt.jorisjonkers.dev/(plus the.testvariants every downstream client carries)."tribelt" to ServicePermission.TRIBELTinDOWNSTREAM_CLIENT_PERMISSIONS.Why this shape
The public site is anonymous, so there is no forward-auth in front of it. The grant is enforced at the authorize endpoint instead, the same way Outline (NOTES) works: only admins and users holding TRIBELT get a code. The ID token already carries
roleswithSERVICE_TRIBELT/ROLE_ADMIN, which the app double-checks. Userinfo does not include roles.No migration:
user_service_permissions.serviceis aVARCHAR(50)without a check constraint, as with NOTES, HERMES and OVERLEAF.Deploy prerequisites
auth.clients.tribelt.secretinsecret/data/auth-api(written before the fleet-infra change lands).AUTH_CLIENTS_TRIBELT_SECRETtemplate line; until then the@Valuedefault applies and the client is unusable in production.Verification
:api:test :api:ktlintCheck :api:detekt: 206/206, clean.:api:integrationTest(OAuth2Flow, ForwardAuth, SecurityFilterChainRouting, Testcontainers): 76/76.