v0.5.9: El Torito boot detection + retroactive re-introspect; static SSO login button
Storage / boot detection - Add El Torito boot-catalog detection to ISO introspection. This is the authoritative "can this boot at all?" signal: any ISO with a boot catalog (BSDs, ESXi, firmware tools, custom spins) is bootable via iPXE sanboot; a data/appliance ISO (e.g. a VMware vCenter bundle) has none and is honestly flagged. Replaces the crude ">1.5 GB ⇒ unbootable" size guess. - Re-introspect stale LOCAL ISOs on startup via an introspection-revision gate (INTROSPECT_REV). ISOs uploaded by an older binary carried a frozen family/boot profile — most visibly a Windows 11 ISO tagged Unknown before the UDF/UTF-16 detection landed, which then showed "won't boot" forever. An upgrade now re-probes and fixes them in place; no delete-and-re-upload. - WebUI bootability() keys off family / kernel / el_torito / remote-source instead of the size heuristic; dashboard family counts now bucket Windows / Linux / other honestly instead of lumping everything non-Windows under "Linux". SSO login button - The "Sign in with …" button keyed off the auth-gated /api/sso, which 401s pre-auth — so the button only survived on a stale in-memory config and vanished instance-wide on any fresh login-page load. Ship a minimal, non-sensitive SSO descriptor (enabled + idp_name + idp_logo_url, no metadata/entity-ID) on the public /api/me; the login card reads that. The button is now static whenever SSO is usable. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
cb51b8db75
commit
06695c3d77
@@ -319,6 +319,12 @@ pub async fn api_me(State(state): State<AppState>, headers: axum::http::HeaderMa
|
||||
// and the logo asset is public, so this leaks nothing sensitive.
|
||||
let has_custom_logo = state.branding.has_any_web_logo();
|
||||
let logo_rev = state.branding.logo_rev();
|
||||
// v0.5.9: ship the non-sensitive SSO descriptor with every /api/me so
|
||||
// the pre-auth login screen can render the "Sign in with …" button
|
||||
// reliably. Previously the button keyed off the auth-gated /api/sso,
|
||||
// which 401s when logged out — the button only survived on a stale
|
||||
// in-memory config and vanished on any fresh login-page load.
|
||||
let sso = state.sso.login_info();
|
||||
if !state.admin.is_configured() {
|
||||
return (
|
||||
StatusCode::OK,
|
||||
@@ -327,6 +333,7 @@ pub async fn api_me(State(state): State<AppState>, headers: axum::http::HeaderMa
|
||||
"authenticated": false,
|
||||
"has_custom_logo": has_custom_logo,
|
||||
"logo_rev": logo_rev,
|
||||
"sso": sso,
|
||||
})),
|
||||
)
|
||||
.into_response();
|
||||
@@ -343,6 +350,7 @@ pub async fn api_me(State(state): State<AppState>, headers: axum::http::HeaderMa
|
||||
"session_user": u,
|
||||
"has_custom_logo": has_custom_logo,
|
||||
"logo_rev": logo_rev,
|
||||
"sso": sso,
|
||||
})),
|
||||
)
|
||||
.into_response(),
|
||||
@@ -353,6 +361,7 @@ pub async fn api_me(State(state): State<AppState>, headers: axum::http::HeaderMa
|
||||
"authenticated": false,
|
||||
"has_custom_logo": has_custom_logo,
|
||||
"logo_rev": logo_rev,
|
||||
"sso": sso,
|
||||
})),
|
||||
)
|
||||
.into_response(),
|
||||
|
||||
Reference in New Issue
Block a user