feat: complete evidence restructuring worktree
This commit is contained in:
+18
-19
@@ -1,7 +1,7 @@
|
||||
# Configurazione del provider Authentik
|
||||
# Authentik provider configuration
|
||||
|
||||
Il protocollo browser di ThothII è OIDC generico. Authentik fornisce il catalogo gruppi e il
|
||||
provider di identità senza introdurre un percorso di login proprietario.
|
||||
ThothII uses generic OIDC in the browser. Authentik provides the identity provider and group
|
||||
catalog without adding a proprietary login flow.
|
||||
|
||||
```mermaid
|
||||
sequenceDiagram
|
||||
@@ -17,26 +17,25 @@ sequenceDiagram
|
||||
ThothII-->>Browser: Opaque session
|
||||
```
|
||||
|
||||
## Provider OIDC
|
||||
## OIDC provider
|
||||
|
||||
1. Creare applicazione e provider OAuth2/OIDC.
|
||||
2. Registrare esattamente `PUBLIC_URL/api/auth/oidc/callback`.
|
||||
3. Abilitare gli scope `openid`, `profile` ed `email`.
|
||||
4. Configurare un claim diretto `groups` come array di stringhe.
|
||||
1. Create an OAuth2/OIDC application and provider.
|
||||
2. Register exactly `PUBLIC_URL/api/auth/oidc/callback`.
|
||||
3. Enable the `openid`, `profile`, and `email` scopes.
|
||||
4. Configure a direct `groups` claim as an array of strings.
|
||||
|
||||
## Catalogo gruppi
|
||||
## Group catalog
|
||||
|
||||
Creare un account di servizio dedicato con sola lettura dei gruppi. Conservare il token nel
|
||||
bundle protetto come `THT_AUTHENTIK_API_TOKEN`.
|
||||
Create a dedicated service account with read-only access to groups. Store its token in the
|
||||
protected bundle as `THT_AUTHENTIK_API_TOKEN`.
|
||||
|
||||
Mappare in `auth.yaml` i nomi esatti dei gruppi aziendali ai ruoli ThothII `user` e `admin`.
|
||||
Gruppi non mappati vengono ignorati; un gruppo configurato ma assente genera un errore chiuso.
|
||||
Map the exact enterprise group names to the ThothII `user` and `admin` roles in `auth.yaml`.
|
||||
Unmapped groups are ignored. A configured group that does not exist produces a closed error.
|
||||
|
||||
## Diagnostica
|
||||
## Diagnostics
|
||||
|
||||
`tht auth check` controlla discovery, issuer, JWKS, accesso al catalogo e presenza dei gruppi
|
||||
configurati. L'opzione `--interactive` aggiunge la verifica dell'identità tramite device flow,
|
||||
quando il provider la supporta.
|
||||
`tht auth check` checks discovery, the issuer, JWKS, catalog access, and the configured groups.
|
||||
The `--interactive` option also verifies identity through device flow when the provider supports it.
|
||||
|
||||
Ruotare separatamente secret OIDC e token del catalogo gruppi. Nessuno dei due deve comparire in
|
||||
YAML, cronologia shell, log o output diagnostico.
|
||||
Rotate the OIDC secret and group-catalog token separately. Neither may appear in YAML, shell
|
||||
history, logs, or diagnostic output.
|
||||
|
||||
Reference in New Issue
Block a user