admin-guide/sign-in-options/index.md

3.4 KiB

id title description tags lang
sign-in-options Sign-in options The identity providers f451 supports, how they compare, and why there are no local accounts.
admin
auth
en

Sign-in options

f451 never stores a password. Every sign-in goes through an external identity provider, and every permission check after that goes through the Git provider behind the space a person is looking at — see Principles in the Developer Guide in the developer guide for why that split exists. This page is about the first half: who is allowed to sign in at all.

Why no local accounts

A local account system would need its own password reset, its own lockout policy, its own audit trail — none of which f451 could do better than the identity provider your organisation already runs and already trusts for offboarding. Instead, f451 delegates entirely: one configured OIDC issuer, optionally GitHub as a second method, and permissions that come from the linked Forgejo or GitHub account rather than from anything f451 tracks itself.

Comparison

Provider Use case What f451 needs Notes
Microsoft Entra ID Production, organisation-managed identities F451_OIDC_ISSUER/_CLIENT_ID/_CLIENT_SECRET/_REDIRECT_URL, F451_TOKEN_KEY See entra-id. Sign-in only — reading/writing still needs a separately connected Forgejo or GitHub account, unless Forgejo itself also authenticates against Entra (see next row).
Forgejo (bundled) Local development, or production where Forgejo is the single identity source Same OIDC variables, pointed at Forgejo's built-in OIDC provider See forgejo-identity-provider. Can also make the first sign-in link the Forgejo account automatically.
Other OIDC provider (Keycloak, Authentik, Zitadel, Okta, Google, …) Any organisation already standardised on a different IdP Same OIDC variables, pointed at that provider's issuer Configuration only — f451 speaks standard OpenID Connect, nothing provider-specific.
GitHub Teams whose spaces already live on GitHub F451_GITHUB_LOGIN=1, F451_GITHUB_OAUTH_CLIENT_ID/_SECRET See github-sign-in. Works with or without an OIDC provider configured; signing in with GitHub also links the GitHub account in the same step.

Only one OIDC issuer can be configured at a time — f451 does not offer a picker between several OIDC providers. GitHub sign-in is independent of that and can be enabled alongside it, or on its own.

What sign-in does and does not unlock

Signing in only authenticates who someone is. It does not, by itself, grant access to any space's content:

Important

Reading and writing follow the linked Git account, not the sign-in method. A person who signs in but never connects a Forgejo or GitHub account sees no spaces at all — not because f451 hides them, but because there is no permission to check against.

See spaces-and-git-providers for how a space is tied to a repository, and the User Guide's Getting started page for what connecting an account looks like for the person doing it.

One person, several identities

Because each sign-in method produces its own identity, a person who signs in once through Entra and once through GitHub becomes two separate f451 users, each with its own set of connected Git accounts — see github-sign-in for the practical consequence of that.