G3.1: OIDC live — sign in to Windy Git with a Windy account

Client 'windy-git' registered on account-server; Gitea auth source 'windy'
added against the discovery document. Auto-registration on, so a Windy account
IS the account — nobody is asked to invent a second identity for the same
person and no local password ever exists.

Proven end to end:
  - app.windygit.com/user/login offers 'Sign in with windy'
  - /user/oauth2/windy -> 307 to account.windyword.ai/oauth/authorize
  - authenticated authorize -> 200, issues a code to the registered callback
  - a bogus evil.example.com redirect_uri -> 'redirect_uri not registered for
    this client'. The anti-phishing check works, which is the whole reason
    redirect URIs are registered rather than accepted.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Grant Whitmer
2026-08-12 10:27:14 -04:00
parent d684cfc2e1
commit b274392e96

View File

@@ -57,6 +57,17 @@ services:
# G2.2 — OIDC only. No local password login, no self-registration. # G2.2 — OIDC only. No local password login, no self-registration.
GITEA__service__DISABLE_REGISTRATION: "true" GITEA__service__DISABLE_REGISTRATION: "true"
GITEA__service__ALLOW_ONLY_EXTERNAL_REGISTRATION: "true" GITEA__service__ALLOW_ONLY_EXTERNAL_REGISTRATION: "true"
# G3.1 — a Windy account IS the account. Signing in with Windy provisions
# the Gitea user on first arrival; nobody is asked to invent a second
# identity for the same person, and no local password ever exists.
GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "true"
GITEA__oauth2_client__USERNAME: email
GITEA__oauth2_client__ACCOUNT_LINKING: auto
# The email is asserted by account-server, which is the authority on it.
# Asking the user to re-verify an address their identity provider already
# verified is friction that buys nothing.
GITEA__oauth2_client__UPDATE_AVATAR: "false"
GITEA__service__REGISTER_EMAIL_CONFIRM: "false"
# G4.3 — heavy bytes to R2 at ZERO egress. Git object databases stay on # G4.3 — heavy bytes to R2 at ZERO egress. Git object databases stay on
# local NVMe (I-3); this covers LFS, attachments, packages, avatars and # local NVMe (I-3); this covers LFS, attachments, packages, avatars and
# Actions artifacts, which is where GitHub's painful bills actually come # Actions artifacts, which is where GitHub's painful bills actually come