feat(saml): wire SAML 2.0 SSO end-to-end (pure-Rust) + Settings/Storage UI consolidation (v0.5.1)
SAML SSO (the config was storage-only since v0.4.5; now it logs you in):
- New openpxe-core::saml — pure-Rust SP built on bergshamra (XML-DSig +
exclusive c14n via RustCrypto, no OpenSSL/xmlsec/libxml2). The static
musl binary stays C-free; samael was rejected for hard-requiring OpenSSL.
* metadata.rs — parse IdP EntityDescriptor (SSO URLs + signing certs),
build our SP metadata.
* authn_request.rs — build + HTTP-Redirect-encode AuthnRequests.
* response.rs — verify the signature against the pinned IdP cert
(trusted_keys_only + strict_verification for XSW),
then enforce Status/Destination/Audience/time-bounds/
signature-scope. Stateless; returns the IDs the HTTP
layer needs.
- http-api saml_routes: GET /api/sso/login (302 to IdP), POST /api/sso/acs
(verify -> InResponseTo correlation / IdP-initiated gating / assertion
replay guard -> mint operator session -> 302), GET /api/sso/metadata.
Added to the pre-auth allowlist; /api/sso config stays gated.
- SsoConfig gains entity_id (SP Entity ID, defaults to public base URL)
and allow_idp_initiated (default off), mirroring FleetDM.
- Access model: any IdP-authenticated, cryptographically-verified user gets
an operator session (single-tier; local admin remains the fallback owner).
- Login page: the "Sign in with <IdP>" button now drives the real flow and
surfaces sso_error redirects.
UI consolidation:
- Removed the Advanced sidebar tab; folded its webhook-notifications +
API-reference cards into a collapsible "Advanced" disclosure at the
bottom of Settings.
- Merged the Storage tab's separate SMB and NFS cards into one "Remote
shares" card with a protocol dropdown and a unified, protocol-badged
table. No backend changes — same /api/smb-shares + /api/nfs-shares.
Tests: 17 SAML core tests (accept + reject tampered/unsigned/wrong-key/
wrong-audience/expired/future/wrong-issuer/non-success) and 6 ACS
integration tests (happy path, IdP-initiated gating, SP correlation,
replay, garbage). Full workspace: 206 tests green, clippy clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
252b557b9c
commit
cbcd63bb14
@@ -797,3 +797,46 @@ tr.unbootable td:first-child { border-left: 3px solid var(--warn); }
|
||||
.logo-preview .info { flex: 1; min-width: 0; }
|
||||
.logo-preview .info .name { color: var(--fg); font-weight: 600; }
|
||||
.logo-preview .info .meta { color: var(--fg-dim); font-size: 12px; margin-top: 2px; }
|
||||
|
||||
/* v0.5.1: collapsible "Advanced" disclosure at the bottom of Settings
|
||||
(the former Advanced sidebar tab). A quiet, full-width toggle that
|
||||
expands to reveal the notification + API-reference cards. */
|
||||
.advanced-disclosure { width: 100%; }
|
||||
.advanced-summary {
|
||||
list-style: none;
|
||||
cursor: pointer;
|
||||
user-select: none;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
padding: 10px 14px;
|
||||
color: var(--fg-dim);
|
||||
font-size: 13px;
|
||||
font-weight: 600;
|
||||
background: var(--bg-panel-2);
|
||||
border: 1px solid var(--border);
|
||||
border-radius: var(--radius);
|
||||
}
|
||||
.advanced-summary:hover { color: var(--fg); }
|
||||
.advanced-summary::-webkit-details-marker { display: none; }
|
||||
.advanced-summary::before {
|
||||
content: "▸";
|
||||
font-size: 11px;
|
||||
transition: transform 0.15s ease;
|
||||
}
|
||||
.advanced-disclosure[open] .advanced-summary::before { transform: rotate(90deg); }
|
||||
|
||||
/* v0.5.1: protocol tag on a unified Remote-shares row (SMB / NFS). */
|
||||
.proto-badge {
|
||||
display: inline-block;
|
||||
font-size: 10px;
|
||||
font-weight: 700;
|
||||
letter-spacing: 0.04em;
|
||||
padding: 1px 6px;
|
||||
margin-right: 8px;
|
||||
border-radius: 4px;
|
||||
vertical-align: middle;
|
||||
background: var(--bg-panel-2);
|
||||
border: 1px solid var(--border);
|
||||
color: var(--fg-dim);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user