You can not select more than 25 topics Topics must start with a chinese character,a letter or number, can include dashes ('-') and can be up to 35 characters long.

edit.tmpl 12 kB

Oauth2 consumer (#679) * initial stuff for oauth2 login, fails on: * login button on the signIn page to start the OAuth2 flow and a callback for each provider Only GitHub is implemented for now * show login button only when the OAuth2 consumer is configured (and activated) * create macaron group for oauth2 urls * prevent net/http in modules (other then oauth2) * use a new data sessions oauth2 folder for storing the oauth2 session data * add missing 2FA when this is enabled on the user * add password option for OAuth2 user , for use with git over http and login to the GUI * add tip for registering a GitHub OAuth application * at startup of Gitea register all configured providers and also on adding/deleting of new providers * custom handling of errors in oauth2 request init + show better tip * add ExternalLoginUser model and migration script to add it to database * link a external account to an existing account (still need to handle wrong login and signup) and remove if user is removed * remove the linked external account from the user his settings * if user is unknown we allow him to register a new account or link it to some existing account * sign up with button on signin page (als change OAuth2Provider structure so we can store basic stuff about providers) * from gorilla/sessions docs: "Important Note: If you aren't using gorilla/mux, you need to wrap your handlers with context.ClearHandler as or else you will leak memory!" (we're using gorilla/sessions for storing oauth2 sessions) * use updated goth lib that now supports getting the OAuth2 user if the AccessToken is still valid instead of re-authenticating (prevent flooding the OAuth2 provider)
9 years ago
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258
  1. {{template "base/head" .}}
  2. <div class="admin edit authentication">
  3. {{template "admin/navbar" .}}
  4. <div class="ui container">
  5. {{template "base/alert" .}}
  6. <h4 class="ui top attached header">
  7. {{.i18n.Tr "admin.auths.edit"}}
  8. </h4>
  9. <div class="ui attached segment">
  10. <form class="ui form" action="{{.Link}}" method="post">
  11. {{.CsrfTokenHtml}}
  12. <input type="hidden" name="id" value="{{.Source.ID}}">
  13. <div class="inline field">
  14. <label>{{$.i18n.Tr "admin.auths.auth_type"}}</label>
  15. <input type="hidden" id="auth_type" name="type" value="{{.Source.Type}}">
  16. <span>{{.Source.TypeName}}</span>
  17. </div>
  18. <div class="required inline field {{if .Err_Name}}error{{end}}">
  19. <label for="name">{{.i18n.Tr "admin.auths.auth_name"}}</label>
  20. <input id="name" name="name" value="{{.Source.Name}}" autofocus required>
  21. </div>
  22. <!-- LDAP and DLDAP -->
  23. {{if or .Source.IsLDAP .Source.IsDLDAP}}
  24. {{ $cfg:=.Source.LDAP }}
  25. <div class="inline required field {{if .Err_SecurityProtocol}}error{{end}}">
  26. <label>{{.i18n.Tr "admin.auths.security_protocol"}}</label>
  27. <div class="ui selection security-protocol dropdown">
  28. <input type="hidden" id="security_protocol" name="security_protocol" value="{{$cfg.SecurityProtocol}}">
  29. <div class="text">{{$cfg.SecurityProtocolName}}</div>
  30. <i class="dropdown icon"></i>
  31. <div class="menu">
  32. {{range .SecurityProtocols}}
  33. <div class="item" data-value="{{.Type}}">{{.Name}}</div>
  34. {{end}}
  35. </div>
  36. </div>
  37. </div>
  38. <div class="required field">
  39. <label for="host">{{.i18n.Tr "admin.auths.host"}}</label>
  40. <input id="host" name="host" value="{{$cfg.Host}}" placeholder="e.g. mydomain.com" required>
  41. </div>
  42. <div class="required field">
  43. <label for="port">{{.i18n.Tr "admin.auths.port"}}</label>
  44. <input id="port" name="port" value="{{$cfg.Port}}" placeholder="e.g. 636" required>
  45. </div>
  46. {{if .Source.IsLDAP}}
  47. <div class="field">
  48. <label for="bind_dn">{{.i18n.Tr "admin.auths.bind_dn"}}</label>
  49. <input id="bind_dn" name="bind_dn" value="{{$cfg.BindDN}}" placeholder="e.g. cn=Search,dc=mydomain,dc=com">
  50. </div>
  51. <input class="fake" type="password">
  52. <div class="field">
  53. <label for="bind_password">{{.i18n.Tr "admin.auths.bind_password"}}</label>
  54. <input id="bind_password" name="bind_password" type="password" value="{{$cfg.BindPassword}}">
  55. <p class="help text red">{{.i18n.Tr "admin.auths.bind_password_helper"}}</p>
  56. </div>
  57. <div class="required field">
  58. <label for="user_base">{{.i18n.Tr "admin.auths.user_base"}}</label>
  59. <input id="user_base" name="user_base" value="{{$cfg.UserBase}}" placeholder="e.g. ou=Users,dc=mydomain,dc=com" required>
  60. </div>
  61. {{end}}
  62. {{if .Source.IsDLDAP}}
  63. <div class="required field">
  64. <label for="user_dn">{{.i18n.Tr "admin.auths.user_dn"}}</label>
  65. <input id="user_dn" name="user_dn" value="{{$cfg.UserDN}}" placeholder="e.g. uid=%s,ou=Users,dc=mydomain,dc=com" required>
  66. </div>
  67. {{end}}
  68. <div class="required field">
  69. <label for="filter">{{.i18n.Tr "admin.auths.filter"}}</label>
  70. <input id="filter" name="filter" value="{{$cfg.Filter}}" placeholder="e.g. (&(objectClass=posixAccount)(uid=%s))" required>
  71. </div>
  72. <div class="field">
  73. <label for="admin_filter">{{.i18n.Tr "admin.auths.admin_filter"}}</label>
  74. <input id="admin_filter" name="admin_filter" value="{{$cfg.AdminFilter}}">
  75. </div>
  76. <div class="field">
  77. <label for="attribute_username">{{.i18n.Tr "admin.auths.attribute_username"}}</label>
  78. <input id="attribute_username" name="attribute_username" value="{{$cfg.AttributeUsername}}" placeholder="{{.i18n.Tr "admin.auths.attribute_username_placeholder"}}">
  79. </div>
  80. <div class="field">
  81. <label for="attribute_name">{{.i18n.Tr "admin.auths.attribute_name"}}</label>
  82. <input id="attribute_name" name="attribute_name" value="{{$cfg.AttributeName}}">
  83. </div>
  84. <div class="field">
  85. <label for="attribute_surname">{{.i18n.Tr "admin.auths.attribute_surname"}}</label>
  86. <input id="attribute_surname" name="attribute_surname" value="{{$cfg.AttributeSurname}}">
  87. </div>
  88. <div class="required field">
  89. <label for="attribute_mail">{{.i18n.Tr "admin.auths.attribute_mail"}}</label>
  90. <input id="attribute_mail" name="attribute_mail" value="{{$cfg.AttributeMail}}" placeholder="e.g. mail" required>
  91. </div>
  92. {{if .Source.IsLDAP}}
  93. <div class="inline field">
  94. <div class="ui checkbox">
  95. <label for="use_paged_search"><strong>{{.i18n.Tr "admin.auths.use_paged_search"}}</strong></label>
  96. <input id="use_paged_search" name="use_paged_search" type="checkbox" {{if $cfg.UsePagedSearch}}checked{{end}}>
  97. </div>
  98. </div>
  99. <div class="field required search-page-size{{if not $cfg.UsePagedSearch}} hide{{end}}">
  100. <label for="search_page_size">{{.i18n.Tr "admin.auths.search_page_size"}}</label>
  101. <input id="search_page_size" name="search_page_size" value="{{if $cfg.UsePagedSearch}}{{$cfg.SearchPageSize}}{{end}}">
  102. </div>
  103. <div class="inline field">
  104. <div class="ui checkbox">
  105. <label><strong>{{.i18n.Tr "admin.auths.attributes_in_bind"}}</strong></label>
  106. <input name="attributes_in_bind" type="checkbox" {{if $cfg.AttributesInBind}}checked{{end}}>
  107. </div>
  108. </div>
  109. {{end}}
  110. {{end}}
  111. <!-- SMTP -->
  112. {{if .Source.IsSMTP}}
  113. {{ $cfg:=.Source.SMTP }}
  114. <div class="inline required field">
  115. <label>{{.i18n.Tr "admin.auths.smtp_auth"}}</label>
  116. <div class="ui selection type dropdown">
  117. <input type="hidden" id="smtp_auth" name="smtp_auth" value="{{$cfg.Auth}}" required>
  118. <div class="text">{{$cfg.Auth}}</div>
  119. <i class="dropdown icon"></i>
  120. <div class="menu">
  121. {{range .SMTPAuths}}
  122. <div class="item" data-value="{{.}}">{{.}}</div>
  123. {{end}}
  124. </div>
  125. </div>
  126. </div>
  127. <div class="required field">
  128. <label for="smtp_host">{{.i18n.Tr "admin.auths.smtphost"}}</label>
  129. <input id="smtp_host" name="smtp_host" value="{{$cfg.Host}}" required>
  130. </div>
  131. <div class="required field">
  132. <label for="smtp_port">{{.i18n.Tr "admin.auths.smtpport"}}</label>
  133. <input id="smtp_port" name="smtp_port" value="{{$cfg.Port}}" required>
  134. </div>
  135. <div class="field">
  136. <label for="allowed_domains">{{.i18n.Tr "admin.auths.allowed_domains"}}</label>
  137. <input id="allowed_domains" name="allowed_domains" value="{{$cfg.AllowedDomains}}">
  138. <p class="help">{{.i18n.Tr "admin.auths.allowed_domains_helper"}}</p>
  139. </div>
  140. {{end}}
  141. <!-- PAM -->
  142. {{if .Source.IsPAM}}
  143. {{ $cfg:=.Source.PAM }}
  144. <div class="required field">
  145. <label for="pam_service_name">{{.i18n.Tr "admin.auths.pam_service_name"}}</label>
  146. <input id="pam_service_name" name="pam_service_name" value="{{$cfg.ServiceName}}" required>
  147. </div>
  148. {{end}}
  149. <!-- OAuth2 -->
  150. {{if .Source.IsOAuth2}}
  151. {{ $cfg:=.Source.OAuth2 }}
  152. <div class="inline required field">
  153. <label>{{.i18n.Tr "admin.auths.oauth2_provider"}}</label>
  154. <div class="ui selection type dropdown">
  155. <input type="hidden" id="oauth2_provider" name="oauth2_provider" value="{{$cfg.Provider}}" required>
  156. <div class="text">{{.CurrentOAuth2Provider.DisplayName}}</div>
  157. <i class="dropdown icon"></i>
  158. <div class="menu">
  159. {{range $key, $value := .OAuth2Providers}}
  160. <div class="item" data-value="{{$key}}">{{$value.DisplayName}}</div>
  161. {{end}}
  162. </div>
  163. </div>
  164. </div>
  165. <div class="required field">
  166. <label for="oauth2_key">{{.i18n.Tr "admin.auths.oauth2_clientID"}}</label>
  167. <input id="oauth2_key" name="oauth2_key" value="{{$cfg.ClientID}}" required>
  168. </div>
  169. <div class="required field">
  170. <label for="oauth2_secret">{{.i18n.Tr "admin.auths.oauth2_clientSecret"}}</label>
  171. <input id="oauth2_secret" name="oauth2_secret" value="{{$cfg.ClientSecret}}" required>
  172. </div>
  173. <div class="open_id_connect_auto_discovery_url required field">
  174. <label for="open_id_connect_auto_discovery_url">{{.i18n.Tr "admin.auths.openIdConnectAutoDiscoveryURL"}}</label>
  175. <input id="open_id_connect_auto_discovery_url" name="open_id_connect_auto_discovery_url" value="{{$cfg.OpenIDConnectAutoDiscoveryURL}}">
  176. </div>
  177. <div class="oauth2_use_custom_url inline field">
  178. <div class="ui checkbox">
  179. <label><strong>{{.i18n.Tr "admin.auths.oauth2_use_custom_url"}}</strong></label>
  180. <input id="oauth2_use_custom_url" name="oauth2_use_custom_url" type="checkbox" {{if $cfg.CustomURLMapping}}checked{{end}}>
  181. </div>
  182. </div>
  183. <div class="oauth2_use_custom_url_field oauth2_auth_url required field">
  184. <label for="oauth2_auth_url">{{.i18n.Tr "admin.auths.oauth2_authURL"}}</label>
  185. <input id="oauth2_auth_url" name="oauth2_auth_url" value="{{if $cfg.CustomURLMapping}}{{$cfg.CustomURLMapping.AuthURL}}v{{end}}">
  186. </div>
  187. <div class="oauth2_use_custom_url_field oauth2_token_url required field">
  188. <label for="oauth2_token_url">{{.i18n.Tr "admin.auths.oauth2_tokenURL"}}</label>
  189. <input id="oauth2_token_url" name="oauth2_token_url" value="{{if $cfg.CustomURLMapping}}{{$cfg.CustomURLMapping.TokenURL}}{{end}}">
  190. </div>
  191. <div class="oauth2_use_custom_url_field oauth2_profile_url required field">
  192. <label for="oauth2_profile_url">{{.i18n.Tr "admin.auths.oauth2_profileURL"}}</label>
  193. <input id="oauth2_profile_url" name="oauth2_profile_url" value="{{if $cfg.CustomURLMapping}}{{$cfg.CustomURLMapping.ProfileURL}}{{end}}">
  194. </div>
  195. <div class="oauth2_use_custom_url_field oauth2_email_url required field">
  196. <label for="oauth2_email_url">{{.i18n.Tr "admin.auths.oauth2_emailURL"}}</label>
  197. <input id="oauth2_email_url" name="oauth2_email_url" value="{{if $cfg.CustomURLMapping}}{{$cfg.CustomURLMapping.EmailURL}}{{end}}">
  198. </div>
  199. {{if .OAuth2DefaultCustomURLMappings}}{{range $key, $value := .OAuth2DefaultCustomURLMappings}}
  200. <input id="{{$key}}_token_url" value="{{$value.TokenURL}}" type="hidden" />
  201. <input id="{{$key}}_auth_url" value="{{$value.AuthURL}}" type="hidden" />
  202. <input id="{{$key}}_profile_url" value="{{$value.ProfileURL}}" type="hidden" />
  203. <input id="{{$key}}_email_url" value="{{$value.EmailURL}}" type="hidden" />
  204. {{end}}{{end}}
  205. {{end}}
  206. <div class="inline field {{if not .Source.IsSMTP}}hide{{end}}">
  207. <div class="ui checkbox">
  208. <label><strong>{{.i18n.Tr "admin.auths.enable_tls"}}</strong></label>
  209. <input name="tls" type="checkbox" {{if .Source.UseTLS}}checked{{end}}>
  210. </div>
  211. </div>
  212. <div class="has-tls inline field {{if not .HasTLS}}hide{{end}}">
  213. <div class="ui checkbox">
  214. <label><strong>{{.i18n.Tr "admin.auths.skip_tls_verify"}}</strong></label>
  215. <input name="skip_verify" type="checkbox" {{if .Source.SkipVerify}}checked{{end}}>
  216. </div>
  217. </div>
  218. {{if .Source.IsLDAP}}
  219. <div class="inline field">
  220. <div class="ui checkbox">
  221. <label><strong>{{.i18n.Tr "admin.auths.syncenabled"}}</strong></label>
  222. <input name="is_sync_enabled" type="checkbox" {{if .Source.IsSyncEnabled}}checked{{end}}>
  223. </div>
  224. </div>
  225. {{end}}
  226. <div class="inline field">
  227. <div class="ui checkbox">
  228. <label><strong>{{.i18n.Tr "admin.auths.activated"}}</strong></label>
  229. <input name="is_active" type="checkbox" {{if .Source.IsActived}}checked{{end}}>
  230. </div>
  231. </div>
  232. <div class="field">
  233. <button class="ui green button">{{.i18n.Tr "admin.auths.update"}}</button>
  234. <div class="ui red button delete-button" data-url="{{$.Link}}/delete" data-id="{{.Source.ID}}">{{.i18n.Tr "admin.auths.delete"}}</div>
  235. </div>
  236. </form>
  237. </div>
  238. </div>
  239. </div>
  240. <div class="ui small basic delete modal">
  241. <div class="ui icon header">
  242. <i class="trash icon"></i>
  243. {{.i18n.Tr "admin.auths.delete_auth_title"}}
  244. </div>
  245. <div class="content">
  246. <p>{{.i18n.Tr "admin.auths.delete_auth_desc"}}</p>
  247. </div>
  248. {{template "base/delete_modal_actions" .}}
  249. </div>
  250. {{template "base/footer" .}}