mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: allow creating manual oidc/github based users (#9000)
* feat: allow creating manual oidc/github based users * Add unit test for oidc and no login type create
This commit is contained in:
+6
-6
@@ -1,15 +1,15 @@
|
||||
Usage: coder users create [flags]
|
||||
|
||||
[1mOptions[0m
|
||||
--disable-login bool
|
||||
Disabling login for a user prevents the user from authenticating via
|
||||
password or IdP login. Authentication requires an API key/token
|
||||
generated by an admin. Be careful when using this flag as it can lock
|
||||
the user out of their account.
|
||||
|
||||
-e, --email string
|
||||
Specifies an email address for the new user.
|
||||
|
||||
--login-type string
|
||||
Optionally specify the login type for the user. Valid values are:
|
||||
password, none, github, oidc. Using 'none' prevents the user from
|
||||
authenticating and requires an API key/token to be generated by an
|
||||
admin.
|
||||
|
||||
-p, --password string
|
||||
Specifies a password for the new user.
|
||||
|
||||
|
||||
+38
-6
@@ -2,6 +2,7 @@ package cli
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
"github.com/go-playground/validator/v10"
|
||||
"golang.org/x/xerrors"
|
||||
@@ -18,6 +19,7 @@ func (r *RootCmd) userCreate() *clibase.Cmd {
|
||||
username string
|
||||
password string
|
||||
disableLogin bool
|
||||
loginType string
|
||||
)
|
||||
client := new(codersdk.Client)
|
||||
cmd := &clibase.Cmd{
|
||||
@@ -54,7 +56,18 @@ func (r *RootCmd) userCreate() *clibase.Cmd {
|
||||
return err
|
||||
}
|
||||
}
|
||||
if password == "" && !disableLogin {
|
||||
userLoginType := codersdk.LoginTypePassword
|
||||
if disableLogin && loginType != "" {
|
||||
return xerrors.New("You cannot specify both --disable-login and --login-type")
|
||||
}
|
||||
if disableLogin {
|
||||
userLoginType = codersdk.LoginTypeNone
|
||||
} else if loginType != "" {
|
||||
userLoginType = codersdk.LoginType(loginType)
|
||||
}
|
||||
|
||||
if password == "" && userLoginType == codersdk.LoginTypePassword {
|
||||
// Generate a random password
|
||||
password, err = cryptorand.StringCharset(cryptorand.Human, 20)
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -66,14 +79,22 @@ func (r *RootCmd) userCreate() *clibase.Cmd {
|
||||
Username: username,
|
||||
Password: password,
|
||||
OrganizationID: organization.ID,
|
||||
DisableLogin: disableLogin,
|
||||
UserLoginType: userLoginType,
|
||||
})
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
authenticationMethod := `Your password is: ` + cliui.DefaultStyles.Field.Render(password)
|
||||
if disableLogin {
|
||||
|
||||
authenticationMethod := ""
|
||||
switch codersdk.LoginType(strings.ToLower(string(userLoginType))) {
|
||||
case codersdk.LoginTypePassword:
|
||||
authenticationMethod = `Your password is: ` + cliui.DefaultStyles.Field.Render(password)
|
||||
case codersdk.LoginTypeNone:
|
||||
authenticationMethod = "Login has been disabled for this user. Contact your administrator to authenticate."
|
||||
case codersdk.LoginTypeGithub:
|
||||
authenticationMethod = `Login is authenticated through GitHub.`
|
||||
case codersdk.LoginTypeOIDC:
|
||||
authenticationMethod = `Login is authenticated through the configured OIDC provider.`
|
||||
}
|
||||
|
||||
_, _ = fmt.Fprintln(inv.Stderr, `A new user has been created!
|
||||
@@ -111,11 +132,22 @@ Create a workspace `+cliui.DefaultStyles.Code.Render("coder create")+`!`)
|
||||
Value: clibase.StringOf(&password),
|
||||
},
|
||||
{
|
||||
Flag: "disable-login",
|
||||
Description: "Disabling login for a user prevents the user from authenticating via password or IdP login. Authentication requires an API key/token generated by an admin. " +
|
||||
Flag: "disable-login",
|
||||
Hidden: true,
|
||||
Description: "Deprecated: Use '--login-type=none'. \nDisabling login for a user prevents the user from authenticating via password or IdP login. Authentication requires an API key/token generated by an admin. " +
|
||||
"Be careful when using this flag as it can lock the user out of their account.",
|
||||
Value: clibase.BoolOf(&disableLogin),
|
||||
},
|
||||
{
|
||||
Flag: "login-type",
|
||||
Description: fmt.Sprintf("Optionally specify the login type for the user. Valid values are: %s. "+
|
||||
"Using 'none' prevents the user from authenticating and requires an API key/token to be generated by an admin.",
|
||||
strings.Join([]string{
|
||||
string(codersdk.LoginTypePassword), string(codersdk.LoginTypeNone), string(codersdk.LoginTypeGithub), string(codersdk.LoginTypeOIDC),
|
||||
}, ", ",
|
||||
)),
|
||||
Value: clibase.StringOf(&loginType),
|
||||
},
|
||||
}
|
||||
return cmd
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user