193 lines
9.0 KiB
HTML
193 lines
9.0 KiB
HTML
<!DOCTYPE html>
|
||
<html lang="en">
|
||
<head>
|
||
|
||
|
||
<meta charset="utf-8">
|
||
<meta http-equiv="X-UA-Compatible" content="IE=edge">
|
||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||
|
||
|
||
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/authentication-local/">
|
||
<link rel="shortcut icon" href="../../img/favicon.ico">
|
||
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
|
||
<title>Local authentication - ThothII Docs</title>
|
||
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
|
||
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
|
||
<link href="../../css/base.css" rel="stylesheet">
|
||
<link rel="stylesheet" href="../../css/highlight.css">
|
||
<link href="../../stylesheets/extra.css" rel="stylesheet">
|
||
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
|
||
<!--[if lt IE 9]>
|
||
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
|
||
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
|
||
<![endif]-->
|
||
|
||
<script src="../../js/jquery-3.2.1.min.js"></script>
|
||
<script src="../../js/bootstrap-3.3.7.min.js"></script>
|
||
<script src="../../js/highlight.pack.js"></script>
|
||
|
||
<base target="_top">
|
||
<script>
|
||
var base_url = '../..';
|
||
var is_top_frame = false;
|
||
|
||
var pageToc = [
|
||
{title: "Local authentication", url: "#_top", children: [
|
||
{title: "Bootstrap", url: "#bootstrap" },
|
||
{title: "User administration", url: "#user-administration" },
|
||
{title: "Session behavior and recovery", url: "#session-behavior-and-recovery" },
|
||
{title: "Projected server installations", url: "#projected-server-installations" },
|
||
]},
|
||
];
|
||
|
||
</script>
|
||
<script src="../../js/base.js"></script>
|
||
<script src="../../javascripts/layout-init.js"></script>
|
||
</head>
|
||
|
||
<body>
|
||
<script>
|
||
if (is_top_frame) { $('body').addClass('wm-top-page'); }
|
||
</script>
|
||
|
||
|
||
|
||
<div class="container-fluid wm-page-content">
|
||
<a name="_top"></a>
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
|
||
|
||
<div class="wm-article-nav pull-right">
|
||
<a href="../authentication-oidc/" class="btn btn-xs btn-default pull-right">
|
||
Next
|
||
<i class="fa fa-chevron-right" aria-hidden="true"></i>
|
||
</a>
|
||
<a href="../authentication-oidc/" class="btn btn-xs btn-link">
|
||
OIDC authentication
|
||
</a>
|
||
</div>
|
||
|
||
<div class="wm-article-nav">
|
||
<a href="../shell-and-language/" class="btn btn-xs btn-default pull-left">
|
||
<i class="fa fa-chevron-left" aria-hidden="true"></i>
|
||
Previous</a><a href="../shell-and-language/" class="btn btn-xs btn-link">
|
||
Display mode and language
|
||
</a>
|
||
</div>
|
||
|
||
</div>
|
||
|
||
|
||
|
||
<h1 id="local-authentication">Local authentication<a class="headerlink" href="#local-authentication" title="Permanent link">¶</a></h1>
|
||
<p>Use local mode for a standalone PC or Mac, with <code>shell.mode: full</code> and
|
||
<code>shell.defaultLocale: en</code> in the installation descriptor. Presentation and
|
||
authentication are independent: selecting full does not create accounts. Omics
|
||
embedded instead uses the <a href="../shell-and-language/">upstream guide</a>, not local users.</p>
|
||
<p>Configure local authentication through <code>tht</code>; passwords are entered at an
|
||
echo-free prompt or read from a protected <code>--password-file</code>, never from a command argument.</p>
|
||
<h2 id="bootstrap">Bootstrap<a class="headerlink" href="#bootstrap" title="Permanent link">¶</a></h2>
|
||
<p>After the installation descriptor and protected secret bundle exist, configure the first enabled
|
||
administrator:</p>
|
||
<pre class="highlight"><code class="language-sh">tht --installation /absolute/path/thothii-installation.yaml auth configure \
|
||
--mode local --public-url http://127.0.0.1:8080 \
|
||
--admin-user <operator-user> --admin-display-name <display-name> \
|
||
--password-file /absolute/path/protected-password-file</code></pre>
|
||
<p>The password file is temporary operator input: keep it private and remove it after configuration.
|
||
The resulting <code>users.yaml</code> contains Argon2id hashes, never plaintext passwords. To use prompts,
|
||
omit the admin and password options in an interactive terminal. <code>tht setup</code> performs the same
|
||
bootstrap before it starts the stack.</p>
|
||
<p>The non-secret local <code>auth.yaml</code> has this exact shape:</p>
|
||
<pre class="highlight"><code class="language-yaml">version: 1
|
||
mode: local
|
||
publicUrl: http://127.0.0.1:8080
|
||
session:
|
||
regularTtlSeconds: 43200
|
||
regularIdleSeconds: 7200
|
||
rememberTtlSeconds: 2592000
|
||
rememberIdleSeconds: 604800
|
||
oidcTtlSeconds: 28800
|
||
local:
|
||
usersFile: users.yaml</code></pre>
|
||
<h2 id="user-administration">User administration<a class="headerlink" href="#user-administration" title="Permanent link">¶</a></h2>
|
||
<pre class="highlight"><code class="language-sh">tht auth user list [--json]
|
||
tht auth user add <username> --role user|admin [--display-name <name>] [--password-file <file>]
|
||
tht auth user set-password <username> [--password-file <file>]
|
||
tht auth user enable <username>
|
||
tht auth user disable <username>
|
||
tht auth user grant <username> --role user|admin
|
||
tht auth user revoke <username> --role user|admin
|
||
tht auth user logout-all <username> --yes</code></pre>
|
||
<p>User commands are unavailable in OIDC mode. The last enabled administrator cannot be disabled or
|
||
demoted. Every password, role, enabled-state, and <code>logout-all</code> change increments the user’s
|
||
<code>authRevision</code>, invalidating its sessions. <code>tht auth status --json</code> is redacted and suitable for
|
||
machine use; JSON output is pristine on stdout.</p>
|
||
<h2 id="session-behavior-and-recovery">Session behavior and recovery<a class="headerlink" href="#session-behavior-and-recovery" title="Permanent link">¶</a></h2>
|
||
<p>Full shows its own login form and, after login, the verified display name in its
|
||
header. The name menu contains Log out. This sends a CSRF-protected request to
|
||
<code>/api/auth/logout</code>, revokes the session and returns to login. Language/theme
|
||
preferences may remain in the browser; they are not credentials.</p>
|
||
<p>An ordinary login expires after 2 hours idle or 12 hours absolute. Selecting <strong>Remember me</strong> makes
|
||
the cookie persistent and changes the limits to 7 days idle or 30 days absolute. Remembered
|
||
sessions survive a browser and backend restart, but not a user revision change, configuration
|
||
revision change, logout, or restore. Restore does not include sessions or OIDC state and requires
|
||
every user to authenticate again.</p>
|
||
<p>If access is lost, use <code>tht auth user set-password</code>, <code>enable</code>, role changes, or <code>logout-all</code> as
|
||
appropriate, then log in again. Do not copy passwords, hashes, cookies, CSRF values, or secret
|
||
values into tickets, logs, or evidence.</p>
|
||
<p>Check readiness with <code>tht auth check</code>; add <code>--json</code> for the machine contract. Use
|
||
<code>tht doctor --json</code> for the aggregate installation report.</p>
|
||
<h2 id="projected-server-installations">Projected server installations<a class="headerlink" href="#projected-server-installations" title="Permanent link">¶</a></h2>
|
||
<p>This section applies only when a Linux <code>profile: server</code> descriptor declares a runtime projection.
|
||
The canonical authentication root stays root-owned and is the only authority. The container reads
|
||
only the separate read-only runtime projection selected by <code>CURRENT</code>; it never falls back to the
|
||
canonical files or to a previous generation. Run projected mutations and repairs through the
|
||
root-operated <code>tht</code> commands, and never edit runtime files directly.</p>
|
||
<p>Mac, Windows, and local direct-file authentication remain unchanged when the projection is absent.</p>
|
||
|
||
<br>
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
|
||
|
||
<div class="wm-article-nav pull-right">
|
||
<a href="../authentication-oidc/" class="btn btn-xs btn-default pull-right">
|
||
Next
|
||
<i class="fa fa-chevron-right" aria-hidden="true"></i>
|
||
</a>
|
||
<a href="../authentication-oidc/" class="btn btn-xs btn-link">
|
||
OIDC authentication
|
||
</a>
|
||
</div>
|
||
|
||
<div class="wm-article-nav">
|
||
<a href="../shell-and-language/" class="btn btn-xs btn-default pull-left">
|
||
<i class="fa fa-chevron-left" aria-hidden="true"></i>
|
||
Previous</a><a href="../shell-and-language/" class="btn btn-xs btn-link">
|
||
Display mode and language
|
||
</a>
|
||
</div>
|
||
|
||
</div>
|
||
|
||
<br>
|
||
</div>
|
||
|
||
<footer class="container-fluid wm-page-content">
|
||
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
|
||
</footer>
|
||
|
||
</body>
|
||
</html> |