feat(sso): split SSO providers by delivery model across tiers (#754)

Custom OIDC stays on Community so self-hosters can wire any spec-compliant
OIDC identity provider (Authelia, Keycloak, Authentik, Zitadel, and others).
Google, GitHub, and Okta one-click presets move to Skipper. LDAP / Active
Directory and scoped RBAC are Admiral-only.

Backend enforces the split via a new requireTierForSsoProvider helper in
middleware/tierGates.ts, applied after requireAdmin in all four ssoConfig
mutation handlers. GET /sso/config (list) stays ungated so downgraded
admins can still see previously-configured providers. Invalid provider ids
now 400 before the tier check to avoid leaking tier information.

Frontend adds a compact mode to PaidGate and AdmiralGate for inline
list-item locks, and SSOSection reorders the provider cards as
Custom OIDC > Google > GitHub > Okta > LDAP to reinforce the
free-to-paid progression.

Stale 'SSO is Admiral' copy in AdmiralGate, PaidGate, and the Admiral
upgrade card on the License settings page has been replaced to reflect the
new split. User-facing licensing, SSO, overview, quickstart, and security
docs have been updated with the per-tier provider matrix.
This commit is contained in:
Anso
2026-04-24 15:48:03 -04:00
committed by GitHub
parent 3a20e37625
commit a502da54ee
12 changed files with 256 additions and 36 deletions
+146 -1
View File
@@ -410,7 +410,18 @@ describe('LDAP Filter Escaping', () => {
});
describe('SSO Config Validation on PUT', () => {
// SSO config routes require admin role but no longer require Admiral tier
// Validation tests exercise the required-field checks inside PUT. Per-provider
// tier gates run before validation, so mock the license to Admiral here to keep
// these tests focused on validation logic; tier-gate coverage lives in its own block.
beforeAll(async () => {
const { LicenseService } = await import('../services/LicenseService');
vi.spyOn(LicenseService.getInstance(), 'getTier').mockReturnValue('paid');
vi.spyOn(LicenseService.getInstance(), 'getVariant').mockReturnValue('admiral');
});
afterAll(() => {
vi.restoreAllMocks();
});
it('rejects enabled LDAP config without Server URL', async () => {
const res = await supertest(app)
@@ -623,3 +634,137 @@ describe('SSO OIDC Callback - Additional Error Handling', () => {
expect(res.headers.location).toContain('User');
});
});
describe('SSO Config Tier Gating (per-provider)', () => {
// Per-provider tier rules: Custom OIDC = admin only, preset OIDC (Google/GitHub/Okta) = Skipper+, LDAP = Admiral.
// The matrix below covers mutations only; GET /sso/config (list) intentionally stays tier-ungated so
// downgraded admins can still see previously-configured providers.
let tierSpy: ReturnType<typeof vi.spyOn>;
let variantSpy: ReturnType<typeof vi.spyOn>;
beforeAll(async () => {
const { LicenseService } = await import('../services/LicenseService');
tierSpy = vi.spyOn(LicenseService.getInstance(), 'getTier');
variantSpy = vi.spyOn(LicenseService.getInstance(), 'getVariant');
});
afterAll(() => {
vi.restoreAllMocks();
});
const setTier = (tier: 'community' | 'paid', variant: 'skipper' | 'admiral' | null): void => {
tierSpy.mockReturnValue(tier);
variantSpy.mockReturnValue(variant);
};
describe('community tier', () => {
beforeAll(() => setTier('community', null));
it('PUT oidc_custom succeeds (no tier gate)', async () => {
const res = await supertest(app)
.put('/api/sso/config/oidc_custom')
.set('Authorization', `Bearer ${adminToken}`)
.send({ enabled: false });
expect(res.status).toBe(200);
});
it('PUT oidc_google returns 403 PAID_REQUIRED', async () => {
const res = await supertest(app)
.put('/api/sso/config/oidc_google')
.set('Authorization', `Bearer ${adminToken}`)
.send({ enabled: false });
expect(res.status).toBe(403);
expect(res.body.code).toBe('PAID_REQUIRED');
});
it('PUT ldap returns 403 PAID_REQUIRED (tier check precedes variant check)', async () => {
const res = await supertest(app)
.put('/api/sso/config/ldap')
.set('Authorization', `Bearer ${adminToken}`)
.send({ enabled: false });
expect(res.status).toBe(403);
expect(res.body.code).toBe('PAID_REQUIRED');
});
it('DELETE oidc_github returns 403 PAID_REQUIRED', async () => {
const res = await supertest(app)
.delete('/api/sso/config/oidc_github')
.set('Authorization', `Bearer ${adminToken}`);
expect(res.status).toBe(403);
expect(res.body.code).toBe('PAID_REQUIRED');
});
it('POST oidc_okta/test returns 403 PAID_REQUIRED', async () => {
const res = await supertest(app)
.post('/api/sso/config/oidc_okta/test')
.set('Authorization', `Bearer ${adminToken}`);
expect(res.status).toBe(403);
expect(res.body.code).toBe('PAID_REQUIRED');
});
it('GET /sso/config (list) still returns 200 — list is tier-ungated', async () => {
const res = await supertest(app)
.get('/api/sso/config')
.set('Authorization', `Bearer ${adminToken}`);
expect(res.status).toBe(200);
expect(Array.isArray(res.body)).toBe(true);
});
});
describe('skipper tier', () => {
beforeAll(() => setTier('paid', 'skipper'));
it('PUT oidc_custom succeeds', async () => {
const res = await supertest(app)
.put('/api/sso/config/oidc_custom')
.set('Authorization', `Bearer ${adminToken}`)
.send({ enabled: false });
expect(res.status).toBe(200);
});
it('PUT oidc_google succeeds', async () => {
const res = await supertest(app)
.put('/api/sso/config/oidc_google')
.set('Authorization', `Bearer ${adminToken}`)
.send({ enabled: false });
expect(res.status).toBe(200);
});
it('PUT ldap returns 403 ADMIRAL_REQUIRED', async () => {
const res = await supertest(app)
.put('/api/sso/config/ldap')
.set('Authorization', `Bearer ${adminToken}`)
.send({ enabled: false });
expect(res.status).toBe(403);
expect(res.body.code).toBe('ADMIRAL_REQUIRED');
});
it('DELETE ldap returns 403 ADMIRAL_REQUIRED', async () => {
const res = await supertest(app)
.delete('/api/sso/config/ldap')
.set('Authorization', `Bearer ${adminToken}`);
expect(res.status).toBe(403);
expect(res.body.code).toBe('ADMIRAL_REQUIRED');
});
});
describe('admiral tier', () => {
beforeAll(() => setTier('paid', 'admiral'));
it('PUT ldap succeeds', async () => {
const res = await supertest(app)
.put('/api/sso/config/ldap')
.set('Authorization', `Bearer ${adminToken}`)
.send({ enabled: false });
expect(res.status).toBe(200);
});
it('PUT oidc_okta succeeds', async () => {
const res = await supertest(app)
.put('/api/sso/config/oidc_okta')
.set('Authorization', `Bearer ${adminToken}`)
.send({ enabled: false });
expect(res.status).toBe(200);
});
});
});