feat(saml): wire SAML 2.0 SSO end-to-end (pure-Rust) + Settings/Storage UI consolidation (v0.5.1)
SAML SSO (the config was storage-only since v0.4.5; now it logs you in):
- New openpxe-core::saml — pure-Rust SP built on bergshamra (XML-DSig +
exclusive c14n via RustCrypto, no OpenSSL/xmlsec/libxml2). The static
musl binary stays C-free; samael was rejected for hard-requiring OpenSSL.
* metadata.rs — parse IdP EntityDescriptor (SSO URLs + signing certs),
build our SP metadata.
* authn_request.rs — build + HTTP-Redirect-encode AuthnRequests.
* response.rs — verify the signature against the pinned IdP cert
(trusted_keys_only + strict_verification for XSW),
then enforce Status/Destination/Audience/time-bounds/
signature-scope. Stateless; returns the IDs the HTTP
layer needs.
- http-api saml_routes: GET /api/sso/login (302 to IdP), POST /api/sso/acs
(verify -> InResponseTo correlation / IdP-initiated gating / assertion
replay guard -> mint operator session -> 302), GET /api/sso/metadata.
Added to the pre-auth allowlist; /api/sso config stays gated.
- SsoConfig gains entity_id (SP Entity ID, defaults to public base URL)
and allow_idp_initiated (default off), mirroring FleetDM.
- Access model: any IdP-authenticated, cryptographically-verified user gets
an operator session (single-tier; local admin remains the fallback owner).
- Login page: the "Sign in with <IdP>" button now drives the real flow and
surfaces sso_error redirects.
UI consolidation:
- Removed the Advanced sidebar tab; folded its webhook-notifications +
API-reference cards into a collapsible "Advanced" disclosure at the
bottom of Settings.
- Merged the Storage tab's separate SMB and NFS cards into one "Remote
shares" card with a protocol dropdown and a unified, protocol-badged
table. No backend changes — same /api/smb-shares + /api/nfs-shares.
Tests: 17 SAML core tests (accept + reject tampered/unsigned/wrong-key/
wrong-audience/expired/future/wrong-issuer/non-success) and 6 ACS
integration tests (happy path, IdP-initiated gating, SP correlation,
replay, garbage). Full workspace: 206 tests green, clippy clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
252b557b9c
commit
cbcd63bb14
+15
-1
@@ -12,7 +12,7 @@ members = [
|
||||
]
|
||||
|
||||
[workspace.package]
|
||||
version = "0.5.0"
|
||||
version = "0.5.1"
|
||||
edition = "2021"
|
||||
rust-version = "1.95"
|
||||
license = "MIT OR Apache-2.0"
|
||||
@@ -71,6 +71,20 @@ nfs3_types = "0.5"
|
||||
# to match reqwest and stay musl-static-friendly — no OpenSSL.
|
||||
lettre = { version = "0.11", default-features = false, features = ["smtp-transport", "tokio1-rustls-tls", "builder", "hostname"] }
|
||||
|
||||
# v0.5.1: pure-Rust SAML 2.0 Service Provider. bergshamra does XML-DSig
|
||||
# verification + exclusive c14n with RustCrypto (no OpenSSL/xmlsec/libxml2
|
||||
# C deps), so the static musl binary stays OpenSSL-free — samael was
|
||||
# rejected precisely because it hard-requires OpenSSL. We build the thin
|
||||
# SP layer (AuthnRequest, metadata parse, SAMLResponse semantics) on top.
|
||||
bergshamra = "0.4"
|
||||
roxmltree = "0.21"
|
||||
quick-xml = "0.40"
|
||||
x509-parser = "0.18"
|
||||
# flate2 default backend is miniz_oxide (pure Rust) — do NOT enable the
|
||||
# zlib/zlib-ng C backends, which would break the musl-static build.
|
||||
flate2 = "1.1"
|
||||
base64 = "0.22"
|
||||
|
||||
openpxe-core = { path = "crates/core" }
|
||||
openpxe-dhcp-proxy = { path = "crates/dhcp-proxy" }
|
||||
openpxe-tftp = { path = "crates/tftp" }
|
||||
|
||||
Reference in New Issue
Block a user