G3.1: OIDC live — sign in to Windy Git with a Windy account
Client 'windy-git' registered on account-server; Gitea auth source 'windy'
added against the discovery document. Auto-registration on, so a Windy account
IS the account — nobody is asked to invent a second identity for the same
person and no local password ever exists.
Proven end to end:
- app.windygit.com/user/login offers 'Sign in with windy'
- /user/oauth2/windy -> 307 to account.windyword.ai/oauth/authorize
- authenticated authorize -> 200, issues a code to the registered callback
- a bogus evil.example.com redirect_uri -> 'redirect_uri not registered for
this client'. The anti-phishing check works, which is the whole reason
redirect URIs are registered rather than accepted.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -57,6 +57,17 @@ services:
|
||||
# G2.2 — OIDC only. No local password login, no self-registration.
|
||||
GITEA__service__DISABLE_REGISTRATION: "true"
|
||||
GITEA__service__ALLOW_ONLY_EXTERNAL_REGISTRATION: "true"
|
||||
# G3.1 — a Windy account IS the account. Signing in with Windy provisions
|
||||
# the Gitea user on first arrival; nobody is asked to invent a second
|
||||
# identity for the same person, and no local password ever exists.
|
||||
GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "true"
|
||||
GITEA__oauth2_client__USERNAME: email
|
||||
GITEA__oauth2_client__ACCOUNT_LINKING: auto
|
||||
# The email is asserted by account-server, which is the authority on it.
|
||||
# Asking the user to re-verify an address their identity provider already
|
||||
# verified is friction that buys nothing.
|
||||
GITEA__oauth2_client__UPDATE_AVATAR: "false"
|
||||
GITEA__service__REGISTER_EMAIL_CONFIRM: "false"
|
||||
# G4.3 — heavy bytes to R2 at ZERO egress. Git object databases stay on
|
||||
# local NVMe (I-3); this covers LFS, attachments, packages, avatars and
|
||||
# Actions artifacts, which is where GitHub's painful bills actually come
|
||||
|
||||
Reference in New Issue
Block a user