Demo content from demo/admin-guide (0c17989)
This commit is contained in:
parent
8385e2024a
commit
3c566c0cc9
11 changed files with 645 additions and 2 deletions
60
sign-in-options/index.md
Normal file
60
sign-in-options/index.md
Normal file
|
|
@ -0,0 +1,60 @@
|
|||
---
|
||||
id: sign-in-options
|
||||
title: Sign-in options
|
||||
description: The identity providers f451 supports, how they compare, and why there are no local accounts.
|
||||
tags: [admin, auth]
|
||||
lang: en
|
||||
---
|
||||
|
||||
# Sign-in options
|
||||
|
||||
f451 never stores a password. Every sign-in goes through an external
|
||||
identity provider, and every permission check after that goes through the
|
||||
Git provider behind the space a person is looking at — see *Principles* in the Developer Guide
|
||||
in the developer guide for why that split exists. This page is about the
|
||||
first half: who is allowed to sign in at all.
|
||||
|
||||
## Why no local accounts
|
||||
|
||||
A local account system would need its own password reset, its own
|
||||
lockout policy, its own audit trail — none of which f451 could do better
|
||||
than the identity provider your organisation already runs and already
|
||||
trusts for offboarding. Instead, f451 delegates entirely: one configured
|
||||
OIDC issuer, optionally GitHub as a second method, and permissions that
|
||||
come from the linked Forgejo or GitHub account rather than from anything
|
||||
f451 tracks itself.
|
||||
|
||||
## Comparison
|
||||
|
||||
| Provider | Use case | What f451 needs | Notes |
|
||||
|---|---|---|---|
|
||||
| **Microsoft Entra ID** | Production, organisation-managed identities | `F451_OIDC_ISSUER`/`_CLIENT_ID`/`_CLIENT_SECRET`/`_REDIRECT_URL`, `F451_TOKEN_KEY` | See [[entra-id]]. Sign-in only — reading/writing still needs a separately connected Forgejo or GitHub account, unless Forgejo itself also authenticates against Entra (see next row). |
|
||||
| **Forgejo (bundled)** | Local development, or production where Forgejo is the single identity source | Same OIDC variables, pointed at Forgejo's built-in OIDC provider | See [[forgejo-identity-provider]]. Can also make the *first* sign-in link the Forgejo account automatically. |
|
||||
| **Other OIDC provider** (Keycloak, Authentik, Zitadel, Okta, Google, …) | Any organisation already standardised on a different IdP | Same OIDC variables, pointed at that provider's issuer | Configuration only — f451 speaks standard OpenID Connect, nothing provider-specific. |
|
||||
| **GitHub** | Teams whose spaces already live on GitHub | `F451_GITHUB_LOGIN=1`, `F451_GITHUB_OAUTH_CLIENT_ID`/`_SECRET` | See [[github-sign-in]]. Works with or without an OIDC provider configured; signing in with GitHub also links the GitHub account in the same step. |
|
||||
|
||||
Only one OIDC issuer can be configured at a time — f451 does not offer a
|
||||
picker between several OIDC providers. GitHub sign-in is independent of
|
||||
that and can be enabled alongside it, or on its own.
|
||||
|
||||
## What sign-in does and does not unlock
|
||||
|
||||
Signing in only authenticates *who someone is*. It does not, by itself,
|
||||
grant access to any space's content:
|
||||
|
||||
> [!IMPORTANT]
|
||||
> **Reading and writing follow the linked Git account, not the sign-in
|
||||
> method.** A person who signs in but never connects a Forgejo or GitHub
|
||||
> account sees no spaces at all — not because f451 hides them, but because
|
||||
> there is no permission to check against.
|
||||
|
||||
See [[spaces-and-git-providers]] for how a space is tied to a repository,
|
||||
and the User Guide's *Getting started* page for what connecting an account
|
||||
looks like for the person doing it.
|
||||
|
||||
## One person, several identities
|
||||
|
||||
Because each sign-in method produces its own identity, a person who signs
|
||||
in once through Entra and once through GitHub becomes **two** separate
|
||||
f451 users, each with its own set of connected Git accounts — see
|
||||
[[github-sign-in]] for the practical consequence of that.
|
||||
Loading…
Add table
Add a link
Reference in a new issue