mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: Allow hiding password auth, changing OpenID Connect text and OpenID Connect icon (#5101)
* Allow hiding password entry, changing OpenID Connect text and OpenID Connect icon * Docs * Cleaning * Fix Prettier and Go test and TS compile error * Fix LoginPage test * Prettier * Fix storybook * Add query param to un-hide password auth * Cleaning * Hide password by default when OIDC enabled * Ran prettier, updated goldenfiles and ran "make gen" * Fixed and added LoginPage test * Ran prettier * PR Feedback and split up SignInForm.tsx * Updated golden files * Fix auto-genned-files * make gen -B * Revert provisioner files? * Fix lint error --------- Co-authored-by: Kyle Carberry <kyle@coder.com>
This commit is contained in:
co-authored by
Kyle Carberry
parent
480f3b6e43
commit
69fce0488e
@@ -131,6 +131,13 @@ CODER_OIDC_IGNORE_EMAIL_VERIFIED=true
|
||||
|
||||
When a new user is created, the `preferred_username` claim becomes the username. If this claim is empty, the email address will be stripped of the domain, and become the username (e.g. `example@coder.com` becomes `example`).
|
||||
|
||||
If you'd like to change the OpenID Connect button text and/or icon, you can configure them like so:
|
||||
|
||||
```console
|
||||
CODER_OIDC_SIGN_IN_TEXT="Sign in with Gitea"
|
||||
CODER_OIDC_ICON_URL=https://gitea.io/images/gitea.png
|
||||
```
|
||||
|
||||
## SCIM (enterprise)
|
||||
|
||||
Coder supports user provisioning and deprovisioning via SCIM 2.0 with header
|
||||
|
||||
@@ -562,6 +562,17 @@ curl -X GET http://coder-server:8080/api/v2/config/deployment \
|
||||
"usage": "string",
|
||||
"value": ["string"]
|
||||
},
|
||||
"icon_url": {
|
||||
"default": "string",
|
||||
"enterprise": true,
|
||||
"flag": "string",
|
||||
"hidden": true,
|
||||
"name": "string",
|
||||
"secret": true,
|
||||
"shorthand": "string",
|
||||
"usage": "string",
|
||||
"value": "string"
|
||||
},
|
||||
"ignore_email_verified": {
|
||||
"default": true,
|
||||
"enterprise": true,
|
||||
@@ -595,6 +606,17 @@ curl -X GET http://coder-server:8080/api/v2/config/deployment \
|
||||
"usage": "string",
|
||||
"value": ["string"]
|
||||
},
|
||||
"sign_in_text": {
|
||||
"default": "string",
|
||||
"enterprise": true,
|
||||
"flag": "string",
|
||||
"hidden": true,
|
||||
"name": "string",
|
||||
"secret": true,
|
||||
"shorthand": "string",
|
||||
"usage": "string",
|
||||
"value": "string"
|
||||
},
|
||||
"username_field": {
|
||||
"default": "string",
|
||||
"enterprise": true,
|
||||
|
||||
+95
-9
@@ -663,23 +663,45 @@
|
||||
| `audit_logs` | array of [codersdk.AuditLog](#codersdkauditlog) | false | | |
|
||||
| `count` | integer | false | | |
|
||||
|
||||
## codersdk.AuthMethods
|
||||
## codersdk.AuthMethod
|
||||
|
||||
```json
|
||||
{
|
||||
"github": true,
|
||||
"oidc": true,
|
||||
"password": true
|
||||
"enabled": true
|
||||
}
|
||||
```
|
||||
|
||||
### Properties
|
||||
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
| ---------- | ------- | -------- | ------------ | ----------- |
|
||||
| `github` | boolean | false | | |
|
||||
| `oidc` | boolean | false | | |
|
||||
| `password` | boolean | false | | |
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
| --------- | ------- | -------- | ------------ | ----------- |
|
||||
| `enabled` | boolean | false | | |
|
||||
|
||||
## codersdk.AuthMethods
|
||||
|
||||
```json
|
||||
{
|
||||
"github": {
|
||||
"enabled": true
|
||||
},
|
||||
"oidc": {
|
||||
"enabled": true,
|
||||
"iconUrl": "string",
|
||||
"signInText": "string"
|
||||
},
|
||||
"password": {
|
||||
"enabled": true
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
### Properties
|
||||
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
| ---------- | -------------------------------------------------- | -------- | ------------ | ----------- |
|
||||
| `github` | [codersdk.AuthMethod](#codersdkauthmethod) | false | | |
|
||||
| `oidc` | [codersdk.OIDCAuthMethod](#codersdkoidcauthmethod) | false | | |
|
||||
| `password` | [codersdk.AuthMethod](#codersdkauthmethod) | false | | |
|
||||
|
||||
## codersdk.AuthorizationCheck
|
||||
|
||||
@@ -1898,6 +1920,17 @@ CreateParameterRequest is a structure used to create a new parameter value for a
|
||||
"usage": "string",
|
||||
"value": ["string"]
|
||||
},
|
||||
"icon_url": {
|
||||
"default": "string",
|
||||
"enterprise": true,
|
||||
"flag": "string",
|
||||
"hidden": true,
|
||||
"name": "string",
|
||||
"secret": true,
|
||||
"shorthand": "string",
|
||||
"usage": "string",
|
||||
"value": "string"
|
||||
},
|
||||
"ignore_email_verified": {
|
||||
"default": true,
|
||||
"enterprise": true,
|
||||
@@ -1931,6 +1964,17 @@ CreateParameterRequest is a structure used to create a new parameter value for a
|
||||
"usage": "string",
|
||||
"value": ["string"]
|
||||
},
|
||||
"sign_in_text": {
|
||||
"default": "string",
|
||||
"enterprise": true,
|
||||
"flag": "string",
|
||||
"hidden": true,
|
||||
"name": "string",
|
||||
"secret": true,
|
||||
"shorthand": "string",
|
||||
"usage": "string",
|
||||
"value": "string"
|
||||
},
|
||||
"username_field": {
|
||||
"default": "string",
|
||||
"enterprise": true,
|
||||
@@ -3192,6 +3236,24 @@ CreateParameterRequest is a structure used to create a new parameter value for a
|
||||
| `client_secret` | [codersdk.DeploymentConfigField-string](#codersdkdeploymentconfigfield-string) | false | | |
|
||||
| `enterprise_base_url` | [codersdk.DeploymentConfigField-string](#codersdkdeploymentconfigfield-string) | false | | |
|
||||
|
||||
## codersdk.OIDCAuthMethod
|
||||
|
||||
```json
|
||||
{
|
||||
"enabled": true,
|
||||
"iconUrl": "string",
|
||||
"signInText": "string"
|
||||
}
|
||||
```
|
||||
|
||||
### Properties
|
||||
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
| ------------ | ------- | -------- | ------------ | ----------- |
|
||||
| `enabled` | boolean | false | | |
|
||||
| `iconUrl` | string | false | | |
|
||||
| `signInText` | string | false | | |
|
||||
|
||||
## codersdk.OIDCConfig
|
||||
|
||||
```json
|
||||
@@ -3240,6 +3302,17 @@ CreateParameterRequest is a structure used to create a new parameter value for a
|
||||
"usage": "string",
|
||||
"value": ["string"]
|
||||
},
|
||||
"icon_url": {
|
||||
"default": "string",
|
||||
"enterprise": true,
|
||||
"flag": "string",
|
||||
"hidden": true,
|
||||
"name": "string",
|
||||
"secret": true,
|
||||
"shorthand": "string",
|
||||
"usage": "string",
|
||||
"value": "string"
|
||||
},
|
||||
"ignore_email_verified": {
|
||||
"default": true,
|
||||
"enterprise": true,
|
||||
@@ -3273,6 +3346,17 @@ CreateParameterRequest is a structure used to create a new parameter value for a
|
||||
"usage": "string",
|
||||
"value": ["string"]
|
||||
},
|
||||
"sign_in_text": {
|
||||
"default": "string",
|
||||
"enterprise": true,
|
||||
"flag": "string",
|
||||
"hidden": true,
|
||||
"name": "string",
|
||||
"secret": true,
|
||||
"shorthand": "string",
|
||||
"usage": "string",
|
||||
"value": "string"
|
||||
},
|
||||
"username_field": {
|
||||
"default": "string",
|
||||
"enterprise": true,
|
||||
@@ -3295,9 +3379,11 @@ CreateParameterRequest is a structure used to create a new parameter value for a
|
||||
| `client_id` | [codersdk.DeploymentConfigField-string](#codersdkdeploymentconfigfield-string) | false | | |
|
||||
| `client_secret` | [codersdk.DeploymentConfigField-string](#codersdkdeploymentconfigfield-string) | false | | |
|
||||
| `email_domain` | [codersdk.DeploymentConfigField-array_string](#codersdkdeploymentconfigfield-array_string) | false | | |
|
||||
| `icon_url` | [codersdk.DeploymentConfigField-string](#codersdkdeploymentconfigfield-string) | false | | |
|
||||
| `ignore_email_verified` | [codersdk.DeploymentConfigField-bool](#codersdkdeploymentconfigfield-bool) | false | | |
|
||||
| `issuer_url` | [codersdk.DeploymentConfigField-string](#codersdkdeploymentconfigfield-string) | false | | |
|
||||
| `scopes` | [codersdk.DeploymentConfigField-array_string](#codersdkdeploymentconfigfield-array_string) | false | | |
|
||||
| `sign_in_text` | [codersdk.DeploymentConfigField-string](#codersdkdeploymentconfigfield-string) | false | | |
|
||||
| `username_field` | [codersdk.DeploymentConfigField-string](#codersdkdeploymentconfigfield-string) | false | | |
|
||||
|
||||
## codersdk.Organization
|
||||
|
||||
+11
-3
@@ -139,9 +139,17 @@ curl -X GET http://coder-server:8080/api/v2/users/authmethods \
|
||||
|
||||
```json
|
||||
{
|
||||
"github": true,
|
||||
"oidc": true,
|
||||
"password": true
|
||||
"github": {
|
||||
"enabled": true
|
||||
},
|
||||
"oidc": {
|
||||
"enabled": true,
|
||||
"iconUrl": "string",
|
||||
"signInText": "string"
|
||||
},
|
||||
"password": {
|
||||
"enabled": true
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
@@ -72,12 +72,16 @@ coder server [flags]
|
||||
Consumes $CODER_OIDC_CLIENT_SECRET
|
||||
--oidc-email-domain strings Email domains that clients logging in with OIDC must match.
|
||||
Consumes $CODER_OIDC_EMAIL_DOMAIN
|
||||
--oidc-icon-url string URL pointing to the icon to use on the OepnID Connect login button
|
||||
Consumes $CODER_OIDC_ICON_URL
|
||||
--oidc-ignore-email-verified Ignore the email_verified claim from the upstream provider.
|
||||
Consumes $CODER_OIDC_IGNORE_EMAIL_VERIFIED
|
||||
--oidc-issuer-url string Issuer URL to use for Login with OIDC.
|
||||
Consumes $CODER_OIDC_ISSUER_URL
|
||||
--oidc-scopes strings Scopes to grant when authenticating with OIDC.
|
||||
Consumes $CODER_OIDC_SCOPES (default [openid,profile,email])
|
||||
--oidc-sign-in-text string The text to show on the OpenID Connect sign in button
|
||||
Consumes $CODER_OIDC_SIGN_IN_TEXT (default "OpenID Connect")
|
||||
--oidc-username-field string OIDC claim field to use as the username.
|
||||
Consumes $CODER_OIDC_USERNAME_FIELD (default "preferred_username")
|
||||
--postgres-url string URL of a PostgreSQL database. If empty, PostgreSQL binaries will be downloaded from Maven (https://repo1.maven.org/maven2) and store all data in the config root. Access the built-in database with "coder server postgres-builtin-url".
|
||||
|
||||
Reference in New Issue
Block a user