diff --git a/backend/src/__tests__/sso.test.ts b/backend/src/__tests__/sso.test.ts index 400712d5..74fe4570 100644 --- a/backend/src/__tests__/sso.test.ts +++ b/backend/src/__tests__/sso.test.ts @@ -410,7 +410,18 @@ describe('LDAP Filter Escaping', () => { }); describe('SSO Config Validation on PUT', () => { - // SSO config routes require admin role but no longer require Admiral tier + // Validation tests exercise the required-field checks inside PUT. Per-provider + // tier gates run before validation, so mock the license to Admiral here to keep + // these tests focused on validation logic; tier-gate coverage lives in its own block. + beforeAll(async () => { + const { LicenseService } = await import('../services/LicenseService'); + vi.spyOn(LicenseService.getInstance(), 'getTier').mockReturnValue('paid'); + vi.spyOn(LicenseService.getInstance(), 'getVariant').mockReturnValue('admiral'); + }); + + afterAll(() => { + vi.restoreAllMocks(); + }); it('rejects enabled LDAP config without Server URL', async () => { const res = await supertest(app) @@ -623,3 +634,137 @@ describe('SSO OIDC Callback - Additional Error Handling', () => { expect(res.headers.location).toContain('User'); }); }); + +describe('SSO Config Tier Gating (per-provider)', () => { + // Per-provider tier rules: Custom OIDC = admin only, preset OIDC (Google/GitHub/Okta) = Skipper+, LDAP = Admiral. + // The matrix below covers mutations only; GET /sso/config (list) intentionally stays tier-ungated so + // downgraded admins can still see previously-configured providers. + let tierSpy: ReturnType; + let variantSpy: ReturnType; + + beforeAll(async () => { + const { LicenseService } = await import('../services/LicenseService'); + tierSpy = vi.spyOn(LicenseService.getInstance(), 'getTier'); + variantSpy = vi.spyOn(LicenseService.getInstance(), 'getVariant'); + }); + + afterAll(() => { + vi.restoreAllMocks(); + }); + + const setTier = (tier: 'community' | 'paid', variant: 'skipper' | 'admiral' | null): void => { + tierSpy.mockReturnValue(tier); + variantSpy.mockReturnValue(variant); + }; + + describe('community tier', () => { + beforeAll(() => setTier('community', null)); + + it('PUT oidc_custom succeeds (no tier gate)', async () => { + const res = await supertest(app) + .put('/api/sso/config/oidc_custom') + .set('Authorization', `Bearer ${adminToken}`) + .send({ enabled: false }); + expect(res.status).toBe(200); + }); + + it('PUT oidc_google returns 403 PAID_REQUIRED', async () => { + const res = await supertest(app) + .put('/api/sso/config/oidc_google') + .set('Authorization', `Bearer ${adminToken}`) + .send({ enabled: false }); + expect(res.status).toBe(403); + expect(res.body.code).toBe('PAID_REQUIRED'); + }); + + it('PUT ldap returns 403 PAID_REQUIRED (tier check precedes variant check)', async () => { + const res = await supertest(app) + .put('/api/sso/config/ldap') + .set('Authorization', `Bearer ${adminToken}`) + .send({ enabled: false }); + expect(res.status).toBe(403); + expect(res.body.code).toBe('PAID_REQUIRED'); + }); + + it('DELETE oidc_github returns 403 PAID_REQUIRED', async () => { + const res = await supertest(app) + .delete('/api/sso/config/oidc_github') + .set('Authorization', `Bearer ${adminToken}`); + expect(res.status).toBe(403); + expect(res.body.code).toBe('PAID_REQUIRED'); + }); + + it('POST oidc_okta/test returns 403 PAID_REQUIRED', async () => { + const res = await supertest(app) + .post('/api/sso/config/oidc_okta/test') + .set('Authorization', `Bearer ${adminToken}`); + expect(res.status).toBe(403); + expect(res.body.code).toBe('PAID_REQUIRED'); + }); + + it('GET /sso/config (list) still returns 200 — list is tier-ungated', async () => { + const res = await supertest(app) + .get('/api/sso/config') + .set('Authorization', `Bearer ${adminToken}`); + expect(res.status).toBe(200); + expect(Array.isArray(res.body)).toBe(true); + }); + }); + + describe('skipper tier', () => { + beforeAll(() => setTier('paid', 'skipper')); + + it('PUT oidc_custom succeeds', async () => { + const res = await supertest(app) + .put('/api/sso/config/oidc_custom') + .set('Authorization', `Bearer ${adminToken}`) + .send({ enabled: false }); + expect(res.status).toBe(200); + }); + + it('PUT oidc_google succeeds', async () => { + const res = await supertest(app) + .put('/api/sso/config/oidc_google') + .set('Authorization', `Bearer ${adminToken}`) + .send({ enabled: false }); + expect(res.status).toBe(200); + }); + + it('PUT ldap returns 403 ADMIRAL_REQUIRED', async () => { + const res = await supertest(app) + .put('/api/sso/config/ldap') + .set('Authorization', `Bearer ${adminToken}`) + .send({ enabled: false }); + expect(res.status).toBe(403); + expect(res.body.code).toBe('ADMIRAL_REQUIRED'); + }); + + it('DELETE ldap returns 403 ADMIRAL_REQUIRED', async () => { + const res = await supertest(app) + .delete('/api/sso/config/ldap') + .set('Authorization', `Bearer ${adminToken}`); + expect(res.status).toBe(403); + expect(res.body.code).toBe('ADMIRAL_REQUIRED'); + }); + }); + + describe('admiral tier', () => { + beforeAll(() => setTier('paid', 'admiral')); + + it('PUT ldap succeeds', async () => { + const res = await supertest(app) + .put('/api/sso/config/ldap') + .set('Authorization', `Bearer ${adminToken}`) + .send({ enabled: false }); + expect(res.status).toBe(200); + }); + + it('PUT oidc_okta succeeds', async () => { + const res = await supertest(app) + .put('/api/sso/config/oidc_okta') + .set('Authorization', `Bearer ${adminToken}`) + .send({ enabled: false }); + expect(res.status).toBe(200); + }); + }); +}); diff --git a/backend/src/middleware/tierGates.ts b/backend/src/middleware/tierGates.ts index af9bc3cb..1dd49d24 100644 --- a/backend/src/middleware/tierGates.ts +++ b/backend/src/middleware/tierGates.ts @@ -64,6 +64,17 @@ export const requireScheduledTaskTier = (action: string, req: Request, res: Resp return requireAdmiral(req, res); }; +/** + * Tier gate for SSO providers. The split is by delivery (turnkey vs self-configured), not by + * protocol: Custom OIDC stays free so self-hosters can wire any OIDC IdP (Authelia, Keycloak, + * Authentik, Zitadel); paid tiers get one-click presets and LDAP/AD. + */ +export const requireTierForSsoProvider = (provider: string, req: Request, res: Response): boolean => { + if (provider === 'oidc_custom') return true; + if (provider === 'ldap') return requireAdmiral(req, res); + return requirePaid(req, res); +}; + /** 400s when the request has no object body. Used by endpoints that always expect JSON input. */ export const requireBody = (req: Request, res: Response): boolean => { if (!req.body || typeof req.body !== 'object') { diff --git a/backend/src/routes/ssoConfig.ts b/backend/src/routes/ssoConfig.ts index d9e75488..5b692820 100644 --- a/backend/src/routes/ssoConfig.ts +++ b/backend/src/routes/ssoConfig.ts @@ -1,12 +1,19 @@ import { Router, type Request, type Response } from 'express'; import { DatabaseService } from '../services/DatabaseService'; import { SSOService, type SSOProviderConfig } from '../services/SSOService'; -import { requireAdmin } from '../middleware/tierGates'; +import { requireAdmin, requireTierForSsoProvider } from '../middleware/tierGates'; import { rejectApiTokenScope } from '../middleware/apiTokenScope'; const VALID_SSO_PROVIDERS = ['ldap', 'oidc_google', 'oidc_github', 'oidc_okta', 'oidc_custom'] as const; const SSO_SCOPE_MESSAGE = 'API tokens cannot access SSO configuration.'; +/** Reject unknown provider ids before any tier check so invalid inputs 400 rather than leaking a tier-specific 403. */ +function rejectInvalidProvider(provider: string, res: Response): boolean { + if ((VALID_SSO_PROVIDERS as readonly string[]).includes(provider)) return false; + res.status(400).json({ error: 'Invalid SSO provider' }); + return true; +} + function stripSecrets(config: T): Partial { const copy: Partial = { ...config }; delete (copy as { ldapBindPassword?: unknown }).ldapBindPassword; @@ -35,8 +42,11 @@ ssoConfigRouter.get('/', (req: Request, res: Response): void => { ssoConfigRouter.get('/:provider', (req: Request, res: Response): void => { if (rejectApiTokenScope(req, res, SSO_SCOPE_MESSAGE)) return; if (!requireAdmin(req, res)) return; + const provider = String(req.params.provider); + if (rejectInvalidProvider(provider, res)) return; + if (!requireTierForSsoProvider(provider, req, res)) return; try { - const config = SSOService.getInstance().getProviderConfig(String(req.params.provider)); + const config = SSOService.getInstance().getProviderConfig(provider); if (!config) { res.status(404).json({ error: 'Provider not configured' }); return; @@ -51,12 +61,10 @@ ssoConfigRouter.get('/:provider', (req: Request, res: Response): void => { ssoConfigRouter.put('/:provider', (req: Request, res: Response): void => { if (rejectApiTokenScope(req, res, SSO_SCOPE_MESSAGE)) return; if (!requireAdmin(req, res)) return; + const provider = String(req.params.provider); + if (rejectInvalidProvider(provider, res)) return; + if (!requireTierForSsoProvider(provider, req, res)) return; try { - const provider = String(req.params.provider); - if (!(VALID_SSO_PROVIDERS as readonly string[]).includes(provider)) { - res.status(400).json({ error: 'Invalid SSO provider' }); - return; - } const config = { ...req.body, provider } as SSOProviderConfig; if (config.enabled) { @@ -88,10 +96,12 @@ ssoConfigRouter.put('/:provider', (req: Request, res: Response): void => { ssoConfigRouter.delete('/:provider', (req: Request, res: Response): void => { if (rejectApiTokenScope(req, res, SSO_SCOPE_MESSAGE)) return; if (!requireAdmin(req, res)) return; + const provider = String(req.params.provider); + if (rejectInvalidProvider(provider, res)) return; + if (!requireTierForSsoProvider(provider, req, res)) return; try { - const deletedProvider = String(req.params.provider); - SSOService.getInstance().deleteProviderConfig(deletedProvider); - console.log(`[SSO] Config deleted: ${deletedProvider}`); + SSOService.getInstance().deleteProviderConfig(provider); + console.log(`[SSO] Config deleted: ${provider}`); res.json({ success: true, message: 'SSO configuration deleted' }); } catch (error) { console.error('[SSO] Failed to delete SSO config:', error); @@ -102,8 +112,10 @@ ssoConfigRouter.delete('/:provider', (req: Request, res: Response): void => { ssoConfigRouter.post('/:provider/test', async (req: Request, res: Response): Promise => { if (rejectApiTokenScope(req, res, SSO_SCOPE_MESSAGE)) return; if (!requireAdmin(req, res)) return; + const provider = String(req.params.provider); + if (rejectInvalidProvider(provider, res)) return; + if (!requireTierForSsoProvider(provider, req, res)) return; try { - const provider = String(req.params.provider); if (provider === 'ldap') { const result = await SSOService.getInstance().testLdapConnection(); res.json(result); diff --git a/docs/features/licensing.mdx b/docs/features/licensing.mdx index 751a779a..9e2a9731 100644 --- a/docs/features/licensing.mdx +++ b/docs/features/licensing.mdx @@ -21,20 +21,31 @@ Lifetime pricing is an early-adopter offer available for a limited time only. ### Feature breakdown +**Community** includes: +- Unlimited nodes, compose editor, global logs, app store, alerts, and more +- Two-factor authentication (TOTP) +- Custom OIDC single sign-on (works with Authelia, Keycloak, Authentik, Zitadel, Pocket ID, or any spec-compliant OIDC identity provider) + **Skipper** includes everything in Community, plus: - Fleet View with drill-down - Webhooks and stack labels - Atomic deployments and fleet-wide backups - Auto-update policies +- One-click Google, GitHub, and Okta SSO presets **Admiral** includes everything in Skipper, plus: - Unlimited admin and viewer accounts - Scoped RBAC (deployer, node-admin, auditor roles) -- SSO, audit log, and host console +- LDAP / Active Directory authentication +- Audit log and host console - API tokens and private registries - Notification routing - Scheduled operations + + **SSO is available on every tier.** Community users can integrate any OIDC-compliant identity provider through the Custom OIDC option. Paid tiers add turnkey presets (Google, GitHub, Okta) and LDAP / Active Directory. + + ## Free trial Every new Sencho installation starts with a **14-day Skipper trial**. No license key or credit card is required. Skipper features like fleet management, webhooks, atomic deployments, and auto-update policies are unlocked during the trial so you can evaluate them with your real infrastructure. Admiral-exclusive features (SSO, audit log, host console, scoped RBAC, unlimited accounts) require an Admiral license. diff --git a/docs/features/overview.mdx b/docs/features/overview.mdx index ed6e0354..b319b999 100644 --- a/docs/features/overview.mdx +++ b/docs/features/overview.mdx @@ -89,7 +89,7 @@ Create viewer accounts with read-only access to dashboards, logs, and file conte ## SSO & LDAP authentication -Authenticate with your existing identity provider. Sencho supports LDAP/Active Directory, Google, GitHub, and Okta. SSO works alongside password authentication and auto-provisions accounts on first login with configurable role mapping. Admiral only. [Learn more →](/features/sso) +Authenticate with your existing identity provider. Custom OIDC (Authelia, Keycloak, Authentik, any spec-compliant OIDC provider) is available on every tier. Skipper adds one-click Google, GitHub, and Okta presets. Admiral adds LDAP / Active Directory for enterprise directories. SSO works alongside password authentication and auto-provisions accounts on first login with configurable role mapping. [Learn more →](/features/sso) ## Atomic deployments diff --git a/docs/features/sso.mdx b/docs/features/sso.mdx index c6e75e4e..4f50c152 100644 --- a/docs/features/sso.mdx +++ b/docs/features/sso.mdx @@ -3,17 +3,21 @@ title: SSO & LDAP Authentication description: Authenticate with your existing identity provider, including LDAP, Google, GitHub, Okta, and any spec-compliant OIDC provider. --- -Sencho lets your team sign in using existing identity providers instead of managing separate credentials. SSO works **alongside** password authentication; it does not replace it. SSO is available in all Sencho editions, including Community. +Sencho lets your team sign in using existing identity providers instead of managing separate credentials. SSO works **alongside** password authentication; it does not replace it. SSO is available in every Sencho edition; higher tiers add turnkey presets and enterprise directory support. ## Supported providers -| Provider | Protocol | Notes | -|----------|----------|-------| -| **LDAP / Active Directory** | LDAP bind + search | Works with OpenLDAP, Active Directory, FreeIPA, and any LDAPv3 server | -| **Google** | OpenID Connect | Google Workspace or personal Google accounts | -| **GitHub** | OAuth 2.0 | GitHub personal accounts and GitHub orgs | -| **Okta** | OpenID Connect | Any Okta org or Okta-compatible IdP | -| **Custom OIDC** | OpenID Connect | Any spec-compliant OIDC provider: Keycloak, Authentik, Authelia, Zitadel, KanIDM, Pocket ID, and more | +| Provider | Protocol | Tier | Notes | +|----------|----------|------|-------| +| **Custom OIDC** | OpenID Connect | Community | Any spec-compliant OIDC provider: Authelia, Keycloak, Authentik, Zitadel, KanIDM, Pocket ID, and more | +| **Google** | OpenID Connect | Skipper | One-click preset for Google Workspace or personal Google accounts | +| **GitHub** | OAuth 2.0 | Skipper | One-click preset for GitHub personal accounts and GitHub orgs | +| **Okta** | OpenID Connect | Skipper | One-click preset for any Okta org or Okta-compatible IdP | +| **LDAP / Active Directory** | LDAP bind + search | Admiral | Works with OpenLDAP, Active Directory, FreeIPA, and any LDAPv3 server | + + + **Self-hosters on the Community tier** can still integrate Google, GitHub, Okta, or any other identity provider by using the Custom OIDC option pointed at the provider's discovery endpoint. The paid-tier presets add one-click configuration and provider-specific defaults; the underlying protocol is the same. + ## How it works diff --git a/docs/getting-started/sso-quickstart.mdx b/docs/getting-started/sso-quickstart.mdx index 4bfe4f82..a694690a 100644 --- a/docs/getting-started/sso-quickstart.mdx +++ b/docs/getting-started/sso-quickstart.mdx @@ -5,6 +5,10 @@ description: Step-by-step instructions for connecting Sencho to your identity pr SSO can be configured via environment variables (shown below) or from the Settings UI after first boot. + + **Tier availability.** Custom OIDC is available on every tier, including Community. The Google, GitHub, and Okta one-click presets require Skipper or higher. LDAP / Active Directory requires Admiral. See [Licensing & Billing](/features/licensing#feature-breakdown) for the full breakdown. + + ## Google OIDC 1. Go to the [Google Cloud Console](https://console.cloud.google.com/apis/credentials) diff --git a/docs/security.mdx b/docs/security.mdx index 248224d8..26989b68 100644 --- a/docs/security.mdx +++ b/docs/security.mdx @@ -64,7 +64,9 @@ Every Sencho instance includes the foundational security stack. Advanced access- | Feature | Community | Skipper | Admiral | |---------|:---------:|:-------:|:-------:| | Password authentication | ✓ | ✓ | ✓ | -| SSO (LDAP, Google, GitHub, Okta, Custom OIDC) | ✓ | ✓ | ✓ | +| Custom OIDC SSO (Authelia, Keycloak, Authentik, any provider) | ✓ | ✓ | ✓ | +| One-click Google / GitHub / Okta SSO | | ✓ | ✓ | +| LDAP / Active Directory | | | ✓ | | Two-factor authentication (TOTP + backup codes) | ✓ | ✓ | ✓ | | Session management (httpOnly, Secure, SameSite) | ✓ | ✓ | ✓ | | Encryption at rest (AES-256-GCM) | ✓ | ✓ | ✓ | @@ -86,7 +88,11 @@ Changing your password immediately invalidates all other active sessions, so a c ## Single sign-on -Sencho supports five identity providers: **LDAP/Active Directory**, **Google**, **GitHub**, **Okta**, and any **Custom OIDC** provider (Keycloak, Authentik, Authelia, Zitadel, KanIDM, Pocket ID, and others). SSO is available on every tier, including Community. +Sencho supports five identity providers split across tiers by delivery model: + +- **Community**: **Custom OIDC**, which connects to any spec-compliant OpenID Connect provider (Authelia, Keycloak, Authentik, Zitadel, KanIDM, Pocket ID, and others). +- **Skipper**: one-click presets for **Google**, **GitHub**, and **Okta**. +- **Admiral**: **LDAP / Active Directory** for on-premises directories. All OIDC flows use PKCE (Proof Key for Code Exchange) and a cryptographic state parameter to prevent authorization code interception and cross-site request forgery. SSO credentials (client secrets and LDAP bind passwords) are encrypted at rest with AES-256-GCM. diff --git a/frontend/src/components/AdmiralGate.tsx b/frontend/src/components/AdmiralGate.tsx index fc81da84..f99ca86d 100644 --- a/frontend/src/components/AdmiralGate.tsx +++ b/frontend/src/components/AdmiralGate.tsx @@ -6,6 +6,9 @@ import { useLicense } from '@/context/LicenseContext'; interface AdmiralGateProps { children: ReactNode; featureName?: string; + // Inline compact lock for list items (e.g. a single SSO provider card). Skips + // the full-page upsell and dismiss timer; always renders the blurred + pill style. + compact?: boolean; } const DISMISS_KEY = 'sencho-admiral-upgrade-prompt-dismissed'; @@ -16,13 +19,13 @@ function isDismissedFromStorage(): boolean { return !!dismissedAt && Date.now() - parseInt(dismissedAt, 10) < DISMISS_DURATION_MS; } -export function AdmiralGate({ children, featureName = 'This feature' }: AdmiralGateProps) { +export function AdmiralGate({ children, featureName = 'This feature', compact = false }: AdmiralGateProps) { const { isPaid, license } = useLicense(); const [dismissed, setDismissed] = useState(isDismissedFromStorage); if (isPaid && license?.variant === 'admiral') return <>{children}; - if (dismissed) { + if (compact || dismissed) { return (
@@ -46,7 +49,7 @@ export function AdmiralGate({ children, featureName = 'This feature' }: AdmiralG

{featureName} requires Sencho Admiral

- Unlock team features like SSO authentication, audit logging, API tokens, and unlimited user accounts with a Sencho Admiral license. + Unlock team features like LDAP / Active Directory, audit logging, API tokens, and unlimited user accounts with a Sencho Admiral license. For enterprise pricing or questions, contact{' '} licensing@sencho.io.

diff --git a/frontend/src/components/PaidGate.tsx b/frontend/src/components/PaidGate.tsx index c3d76ca0..2293e832 100644 --- a/frontend/src/components/PaidGate.tsx +++ b/frontend/src/components/PaidGate.tsx @@ -6,6 +6,9 @@ import { useLicense } from '@/context/LicenseContext'; interface PaidGateProps { children: ReactNode; featureName?: string; + // Inline compact lock for list items (e.g. a single SSO provider card). Skips + // the full-page upsell and dismiss timer; always renders the blurred + pill style. + compact?: boolean; } const DISMISS_KEY = 'sencho-upgrade-prompt-dismissed'; @@ -16,13 +19,13 @@ function isDismissedFromStorage(): boolean { return !!dismissedAt && Date.now() - parseInt(dismissedAt, 10) < DISMISS_DURATION_MS; } -export function PaidGate({ children, featureName = 'This feature' }: PaidGateProps) { +export function PaidGate({ children, featureName = 'This feature', compact = false }: PaidGateProps) { const { isPaid } = useLicense(); const [dismissed, setDismissed] = useState(isDismissedFromStorage); if (isPaid) return <>{children}; - if (dismissed) { + if (compact || dismissed) { return (
@@ -31,7 +34,7 @@ export function PaidGate({ children, featureName = 'This feature' }: PaidGatePro
- Upgrade to unlock more features + Upgrade to unlock {featureName}
@@ -46,7 +49,7 @@ export function PaidGate({ children, featureName = 'This feature' }: PaidGatePro

{featureName} requires a paid license

- Unlock features like fleet management, viewer accounts, and more with a Skipper or Admiral license. + Unlock features like fleet management, viewer accounts, one-click Google / GitHub / Okta SSO, and more with a Skipper or Admiral license. For enterprise pricing or questions, contact{' '} licensing@sencho.io.

diff --git a/frontend/src/components/SSOSection.tsx b/frontend/src/components/SSOSection.tsx index 9f10a03f..5261b202 100644 --- a/frontend/src/components/SSOSection.tsx +++ b/frontend/src/components/SSOSection.tsx @@ -8,6 +8,8 @@ import { Badge } from '@/components/ui/badge'; import { toast } from '@/components/ui/toast-store'; import { apiFetch } from '@/lib/api'; import { CapabilityGate } from './CapabilityGate'; +import { PaidGate } from './PaidGate'; +import { AdmiralGate } from './AdmiralGate'; import { Loader2, CheckCircle, XCircle } from 'lucide-react'; const ROLE_OPTIONS = [ @@ -42,12 +44,14 @@ interface SSOProviderConfig { oidcEmailClaim?: string; } +// Ordered by tier: Custom OIDC (Community) → preset OIDC (Skipper) → LDAP/AD (Admiral). +// The ordering reinforces the free → paid progression in the UI. const PROVIDERS = [ - { id: 'ldap', label: 'LDAP / Active Directory', type: 'ldap' as const }, + { id: 'oidc_custom', label: 'Custom OIDC', type: 'oidc' as const }, { id: 'oidc_google', label: 'Google', type: 'oidc' as const }, { id: 'oidc_github', label: 'GitHub', type: 'oidc' as const }, { id: 'oidc_okta', label: 'Okta', type: 'oidc' as const }, - { id: 'oidc_custom', label: 'Custom OIDC', type: 'oidc' as const }, + { id: 'ldap', label: 'LDAP / Active Directory', type: 'ldap' as const }, ]; function ProviderCard({ providerId, type, label, initialConfig, onSave }: { @@ -379,6 +383,23 @@ function ProviderCard({ providerId, type, label, initialConfig, onSave }: { ); } +// Mirrors the backend tier split in ssoConfig.ts requireTierForProvider: Custom OIDC +// is free, preset OIDC (Google/GitHub/Okta) requires Skipper+, LDAP requires Admiral. +function ProviderCardWithGate(props: { + providerId: string; + type: 'ldap' | 'oidc'; + label: string; + initialConfig: SSOProviderConfig | null; + onSave: () => void; +}) { + const card = ; + if (props.providerId === 'oidc_custom') return card; + if (props.providerId === 'ldap') { + return {card}; + } + return {card}; +} + export function SSOSection() { const [configs, setConfigs] = useState([]); @@ -399,7 +420,7 @@ export function SSOSection() {
{PROVIDERS.map(p => ( -

Professional tools for solo operators.

    - {['Fleet View with drill-down', 'Viewer accounts (1 admin + 3 viewers)', 'Webhooks & stack labels', 'Atomic deployments & backups', 'Auto-update policies'].map((f) => ( + {['Fleet View with drill-down', 'Viewer accounts (1 admin + 3 viewers)', 'Webhooks & stack labels', 'Atomic deployments & backups', 'Auto-update policies', 'Google / GitHub / Okta SSO'].map((f) => (
  • {f} @@ -208,7 +208,7 @@ export function LicenseSection() { ...(license?.variant === 'skipper' ? ['Everything in Skipper'] : ['Everything in Community']), 'Unlimited accounts & scoped RBAC', ...(license?.variant !== 'skipper' ? ['Fleet View, webhooks & labels', 'Atomic deployments & backups'] : []), - 'SSO, audit log & host console', + 'LDAP/AD, audit log & host console', 'API tokens & private registries', 'Scheduled operations', ].map((f) => (