mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add login type 'none' to prevent password login (#8009)
* feat: add login type 'none' to prevent login Users with this login type must use tokens to authenticate. Tokens must come from some other source, not a /login with password authentication
This commit is contained in:
@@ -1,6 +1,12 @@
|
||||
Usage: coder users create [flags]
|
||||
|
||||
[1mOptions[0m
|
||||
--disable-login bool
|
||||
Disabling login for a user prevents the user from authenticating via
|
||||
password or IdP login. Authentication requires an API key/token
|
||||
generated by an admin. Be careful when using this flag as it can lock
|
||||
the user out of their account.
|
||||
|
||||
-e, --email string
|
||||
Specifies an email address for the new user.
|
||||
|
||||
|
||||
+18
-5
@@ -14,9 +14,10 @@ import (
|
||||
|
||||
func (r *RootCmd) userCreate() *clibase.Cmd {
|
||||
var (
|
||||
email string
|
||||
username string
|
||||
password string
|
||||
email string
|
||||
username string
|
||||
password string
|
||||
disableLogin bool
|
||||
)
|
||||
client := new(codersdk.Client)
|
||||
cmd := &clibase.Cmd{
|
||||
@@ -53,7 +54,7 @@ func (r *RootCmd) userCreate() *clibase.Cmd {
|
||||
return err
|
||||
}
|
||||
}
|
||||
if password == "" {
|
||||
if password == "" && !disableLogin {
|
||||
password, err = cryptorand.StringCharset(cryptorand.Human, 20)
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -65,10 +66,16 @@ func (r *RootCmd) userCreate() *clibase.Cmd {
|
||||
Username: username,
|
||||
Password: password,
|
||||
OrganizationID: organization.ID,
|
||||
DisableLogin: disableLogin,
|
||||
})
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
authenticationMethod := `Your password is: ` + cliui.DefaultStyles.Field.Render(password)
|
||||
if disableLogin {
|
||||
authenticationMethod = "Login has been disabled for this user. Contact your administrator to authenticate."
|
||||
}
|
||||
|
||||
_, _ = fmt.Fprintln(inv.Stderr, `A new user has been created!
|
||||
Share the instructions below to get them started.
|
||||
`+cliui.DefaultStyles.Placeholder.Render("—————————————————————————————————————————————————")+`
|
||||
@@ -78,7 +85,7 @@ https://github.com/coder/coder/releases
|
||||
Run `+cliui.DefaultStyles.Code.Render("coder login "+client.URL.String())+` to authenticate.
|
||||
|
||||
Your email is: `+cliui.DefaultStyles.Field.Render(email)+`
|
||||
Your password is: `+cliui.DefaultStyles.Field.Render(password)+`
|
||||
`+authenticationMethod+`
|
||||
|
||||
Create a workspace `+cliui.DefaultStyles.Code.Render("coder create")+`!`)
|
||||
return nil
|
||||
@@ -103,6 +110,12 @@ Create a workspace `+cliui.DefaultStyles.Code.Render("coder create")+`!`)
|
||||
Description: "Specifies a password for the new user.",
|
||||
Value: clibase.StringOf(&password),
|
||||
},
|
||||
{
|
||||
Flag: "disable-login",
|
||||
Description: "Disabling login for a user prevents the user from authenticating via password or IdP login. Authentication requires an API key/token generated by an admin. " +
|
||||
"Be careful when using this flag as it can lock the user out of their account.",
|
||||
Value: clibase.BoolOf(&disableLogin),
|
||||
},
|
||||
}
|
||||
return cmd
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user