Publish documentation for 2f53512e4d

This commit is contained in:
Gitea Actions
2026-09-26 22:42:08 +00:00
commit cb50f5a6a4
55 changed files with 33829 additions and 0 deletions
+193
View File
@@ -0,0 +1,193 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/authentication-local/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>Local authentication - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "Local authentication", url: "#_top", children: [
{title: "Bootstrap", url: "#bootstrap" },
{title: "User administration", url: "#user-administration" },
{title: "Session behavior and recovery", url: "#session-behavior-and-recovery" },
{title: "Projected server installations", url: "#projected-server-installations" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../authentication-oidc/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../authentication-oidc/" class="btn btn-xs btn-link">
OIDC authentication
</a>
</div>
<div class="wm-article-nav">
<a href="../shell-and-language/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../shell-and-language/" class="btn btn-xs btn-link">
Display mode and language
</a>
</div>
</div>
<h1 id="local-authentication">Local authentication<a class="headerlink" href="#local-authentication" title="Permanent link">&para;</a></h1>
<p>Use local mode for a standalone PC or Mac, with <code>shell.mode: full</code> and
<code>shell.defaultLocale: en</code> in the installation descriptor. Presentation and
authentication are independent: selecting full does not create accounts. Omics
embedded instead uses the <a href="../shell-and-language/">upstream guide</a>, not local users.</p>
<p>Configure local authentication through <code>tht</code>; passwords are entered at an
echo-free prompt or read from a protected <code>--password-file</code>, never from a command argument.</p>
<h2 id="bootstrap">Bootstrap<a class="headerlink" href="#bootstrap" title="Permanent link">&para;</a></h2>
<p>After the installation descriptor and protected secret bundle exist, configure the first enabled
administrator:</p>
<pre class="highlight"><code class="language-sh">tht --installation /absolute/path/thothii-installation.yaml auth configure \
--mode local --public-url http://127.0.0.1:8080 \
--admin-user &lt;operator-user&gt; --admin-display-name &lt;display-name&gt; \
--password-file /absolute/path/protected-password-file</code></pre>
<p>The password file is temporary operator input: keep it private and remove it after configuration.
The resulting <code>users.yaml</code> contains Argon2id hashes, never plaintext passwords. To use prompts,
omit the admin and password options in an interactive terminal. <code>tht setup</code> performs the same
bootstrap before it starts the stack.</p>
<p>The non-secret local <code>auth.yaml</code> has this exact shape:</p>
<pre class="highlight"><code class="language-yaml">version: 1
mode: local
publicUrl: http://127.0.0.1:8080
session:
regularTtlSeconds: 43200
regularIdleSeconds: 7200
rememberTtlSeconds: 2592000
rememberIdleSeconds: 604800
oidcTtlSeconds: 28800
local:
usersFile: users.yaml</code></pre>
<h2 id="user-administration">User administration<a class="headerlink" href="#user-administration" title="Permanent link">&para;</a></h2>
<pre class="highlight"><code class="language-sh">tht auth user list [--json]
tht auth user add &lt;username&gt; --role user|admin [--display-name &lt;name&gt;] [--password-file &lt;file&gt;]
tht auth user set-password &lt;username&gt; [--password-file &lt;file&gt;]
tht auth user enable &lt;username&gt;
tht auth user disable &lt;username&gt;
tht auth user grant &lt;username&gt; --role user|admin
tht auth user revoke &lt;username&gt; --role user|admin
tht auth user logout-all &lt;username&gt; --yes</code></pre>
<p>User commands are unavailable in OIDC mode. The last enabled administrator cannot be disabled or
demoted. Every password, role, enabled-state, and <code>logout-all</code> change increments the user’s
<code>authRevision</code>, invalidating its sessions. <code>tht auth status --json</code> is redacted and suitable for
machine use; JSON output is pristine on stdout.</p>
<h2 id="session-behavior-and-recovery">Session behavior and recovery<a class="headerlink" href="#session-behavior-and-recovery" title="Permanent link">&para;</a></h2>
<p>Full shows its own login form and, after login, the verified display name in its
header. The name menu contains Log out. This sends a CSRF-protected request to
<code>/api/auth/logout</code>, revokes the session and returns to login. Language/theme
preferences may remain in the browser; they are not credentials.</p>
<p>An ordinary login expires after 2 hours idle or 12 hours absolute. Selecting <strong>Remember me</strong> makes
the cookie persistent and changes the limits to 7 days idle or 30 days absolute. Remembered
sessions survive a browser and backend restart, but not a user revision change, configuration
revision change, logout, or restore. Restore does not include sessions or OIDC state and requires
every user to authenticate again.</p>
<p>If access is lost, use <code>tht auth user set-password</code>, <code>enable</code>, role changes, or <code>logout-all</code> as
appropriate, then log in again. Do not copy passwords, hashes, cookies, CSRF values, or secret
values into tickets, logs, or evidence.</p>
<p>Check readiness with <code>tht auth check</code>; add <code>--json</code> for the machine contract. Use
<code>tht doctor --json</code> for the aggregate installation report.</p>
<h2 id="projected-server-installations">Projected server installations<a class="headerlink" href="#projected-server-installations" title="Permanent link">&para;</a></h2>
<p>This section applies only when a Linux <code>profile: server</code> descriptor declares a runtime projection.
The canonical authentication root stays root-owned and is the only authority. The container reads
only the separate read-only runtime projection selected by <code>CURRENT</code>; it never falls back to the
canonical files or to a previous generation. Run projected mutations and repairs through the
root-operated <code>tht</code> commands, and never edit runtime files directly.</p>
<p>Mac, Windows, and local direct-file authentication remain unchanged when the projection is absent.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav pull-right">
<a href="../authentication-oidc/" class="btn btn-xs btn-default pull-right">
Next
<i class="fa fa-chevron-right" aria-hidden="true"></i>
</a>
<a href="../authentication-oidc/" class="btn btn-xs btn-link">
OIDC authentication
</a>
</div>
<div class="wm-article-nav">
<a href="../shell-and-language/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../shell-and-language/" class="btn btn-xs btn-link">
Display mode and language
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>