130 lines
6.3 KiB
HTML
130 lines
6.3 KiB
HTML
<!DOCTYPE html>
|
|
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="utf-8"/>
|
|
<meta content="IE=edge" http-equiv="X-UA-Compatible"/>
|
|
<meta content="width=device-width, initial-scale=1.0" name="viewport"/>
|
|
<link href="https://git.tylconsulting.it/thothii-docs/install/authentik/" rel="canonical"/>
|
|
<link href="../../img/favicon.ico" rel="shortcut icon"/>
|
|
<meta content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" name="viewport"/>
|
|
<title>Authentik - ThothII Docs</title>
|
|
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet"/>
|
|
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet"/>
|
|
<link href="../../css/base.css" rel="stylesheet"/>
|
|
<link href="../../css/highlight.css" rel="stylesheet"/>
|
|
<link href="../../stylesheets/extra.css" rel="stylesheet"/>
|
|
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
|
|
<!--[if lt IE 9]>
|
|
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
|
|
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
|
|
<![endif]-->
|
|
<script src="../../js/jquery-3.2.1.min.js"></script>
|
|
<script src="../../js/bootstrap-3.3.7.min.js"></script>
|
|
<script src="../../js/highlight.pack.js"></script>
|
|
<base target="_top"/>
|
|
<script>
|
|
var base_url = '../..';
|
|
var is_top_frame = false;
|
|
|
|
var pageToc = [
|
|
{title: "Authentik provider configuration", url: "#_top", children: [
|
|
{title: "OIDC provider", url: "#oidc-provider" },
|
|
{title: "Group catalog", url: "#group-catalog" },
|
|
{title: "Diagnostics", url: "#diagnostics" },
|
|
]},
|
|
];
|
|
|
|
</script>
|
|
<script src="../../js/base.js"></script>
|
|
<script src="../../javascripts/layout-init.js"></script>
|
|
</head>
|
|
<body>
|
|
<script>
|
|
if (is_top_frame) { $('body').addClass('wm-top-page'); }
|
|
</script>
|
|
<div class="container-fluid wm-page-content">
|
|
<a name="_top"></a>
|
|
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
|
|
<div class="wm-article-nav pull-right">
|
|
<a class="btn btn-xs btn-default pull-right" href="../../general/pi-configuration/">
|
|
Next
|
|
<i aria-hidden="true" class="fa fa-chevron-right"></i>
|
|
</a>
|
|
<a class="btn btn-xs btn-link" href="../../general/pi-configuration/">
|
|
Model configuration
|
|
</a>
|
|
</div>
|
|
<div class="wm-article-nav">
|
|
<a class="btn btn-xs btn-default pull-left" href="../authentication-oidc/">
|
|
<i aria-hidden="true" class="fa fa-chevron-left"></i>
|
|
Previous</a><a class="btn btn-xs btn-link" href="../authentication-oidc/">
|
|
OIDC authentication
|
|
</a>
|
|
</div>
|
|
</div>
|
|
<h1 id="authentik-provider-configuration">Authentik provider configuration<a class="headerlink" href="#authentik-provider-configuration" title="Permanent link">¶</a></h1>
|
|
<p>For <strong>full with direct OIDC</strong>, ThothII uses generic OIDC in the browser. Authentik
|
|
provides the identity provider and group catalog without adding a proprietary flow.
|
|
The provider/client/group setup below applies to that case only.</p>
|
|
<p>For <strong>embedded in Omics</strong>, retain Omics's existing Authentik authentication and
|
|
configure ThothII as upstream. Omics verifies <code>datamart_builder.access</code> and
|
|
administrator status and the proxy supplies the identity; no additional ThothII
|
|
OIDC client, login or local user is required for that path. Follow the
|
|
<a href="../shell-and-language/">portal integration guide</a>.</p>
|
|
<div class="mermaid">sequenceDiagram
|
|
participant Browser
|
|
participant ThothII
|
|
participant Authentik
|
|
Browser->>ThothII: Sign in
|
|
ThothII->>Authentik: Authorization Code with PKCE
|
|
Authentik-->>Browser: Login and consent
|
|
Browser->>ThothII: Callback with code
|
|
ThothII->>Authentik: Token exchange
|
|
Authentik-->>ThothII: Identity and groups
|
|
ThothII-->>Browser: Opaque session
|
|
</div>
|
|
<h2 id="oidc-provider">OIDC provider<a class="headerlink" href="#oidc-provider" title="Permanent link">¶</a></h2>
|
|
<ol>
|
|
<li>Create an OAuth2/OIDC application and provider.</li>
|
|
<li>Register exactly <code>PUBLIC_URL/api/auth/oidc/callback</code>.</li>
|
|
<li>Enable the <code>openid</code>, <code>profile</code>, and <code>email</code> scopes.</li>
|
|
<li>Configure a direct <code>groups</code> claim as an array of strings.</li>
|
|
</ol>
|
|
<h2 id="group-catalog">Group catalog<a class="headerlink" href="#group-catalog" title="Permanent link">¶</a></h2>
|
|
<p>Create a dedicated service account with read-only access to groups. Store its token in the
|
|
protected bundle as <code>THT_AUTHENTIK_API_TOKEN</code>.</p>
|
|
<p>Map the exact enterprise group names to the ThothII <code>user</code> and <code>admin</code> roles in <code>auth.yaml</code>.
|
|
Unmapped groups are ignored. A configured group that does not exist produces a closed error.</p>
|
|
<h2 id="diagnostics">Diagnostics<a class="headerlink" href="#diagnostics" title="Permanent link">¶</a></h2>
|
|
<p><code>tht auth check</code> checks discovery, the issuer, JWKS, catalog access, and the configured groups.
|
|
The <code>--interactive</code> option also verifies identity through device flow when the provider supports it.</p>
|
|
<p>Rotate the OIDC secret and group-catalog token separately. Neither may appear in YAML, shell
|
|
history, logs, or diagnostic output.</p>
|
|
<br/>
|
|
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
|
|
<div class="wm-article-nav pull-right">
|
|
<a class="btn btn-xs btn-default pull-right" href="../../general/pi-configuration/">
|
|
Next
|
|
<i aria-hidden="true" class="fa fa-chevron-right"></i>
|
|
</a>
|
|
<a class="btn btn-xs btn-link" href="../../general/pi-configuration/">
|
|
Model configuration
|
|
</a>
|
|
</div>
|
|
<div class="wm-article-nav">
|
|
<a class="btn btn-xs btn-default pull-left" href="../authentication-oidc/">
|
|
<i aria-hidden="true" class="fa fa-chevron-left"></i>
|
|
Previous</a><a class="btn btn-xs btn-link" href="../authentication-oidc/">
|
|
OIDC authentication
|
|
</a>
|
|
</div>
|
|
</div>
|
|
<br/>
|
|
</div>
|
|
<footer class="container-fluid wm-page-content">
|
|
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
|
|
</footer>
|
|
<script type="module">import mermaid from "https://unpkg.com/mermaid@10.4.0/dist/mermaid.esm.min.mjs";
|
|
mermaid.initialize({});</script></body>
|
|
</html> |