feat(sso): split SSO providers by delivery model across tiers (#754)

Custom OIDC stays on Community so self-hosters can wire any spec-compliant
OIDC identity provider (Authelia, Keycloak, Authentik, Zitadel, and others).
Google, GitHub, and Okta one-click presets move to Skipper. LDAP / Active
Directory and scoped RBAC are Admiral-only.

Backend enforces the split via a new requireTierForSsoProvider helper in
middleware/tierGates.ts, applied after requireAdmin in all four ssoConfig
mutation handlers. GET /sso/config (list) stays ungated so downgraded
admins can still see previously-configured providers. Invalid provider ids
now 400 before the tier check to avoid leaking tier information.

Frontend adds a compact mode to PaidGate and AdmiralGate for inline
list-item locks, and SSOSection reorders the provider cards as
Custom OIDC > Google > GitHub > Okta > LDAP to reinforce the
free-to-paid progression.

Stale 'SSO is Admiral' copy in AdmiralGate, PaidGate, and the Admiral
upgrade card on the License settings page has been replaced to reflect the
new split. User-facing licensing, SSO, overview, quickstart, and security
docs have been updated with the per-tier provider matrix.
This commit is contained in:
Anso
2026-04-24 15:48:03 -04:00
committed by GitHub
parent 3a20e37625
commit a502da54ee
12 changed files with 256 additions and 36 deletions
+11
View File
@@ -64,6 +64,17 @@ export const requireScheduledTaskTier = (action: string, req: Request, res: Resp
return requireAdmiral(req, res);
};
/**
* Tier gate for SSO providers. The split is by delivery (turnkey vs self-configured), not by
* protocol: Custom OIDC stays free so self-hosters can wire any OIDC IdP (Authelia, Keycloak,
* Authentik, Zitadel); paid tiers get one-click presets and LDAP/AD.
*/
export const requireTierForSsoProvider = (provider: string, req: Request, res: Response): boolean => {
if (provider === 'oidc_custom') return true;
if (provider === 'ldap') return requireAdmiral(req, res);
return requirePaid(req, res);
};
/** 400s when the request has no object body. Used by endpoints that always expect JSON input. */
export const requireBody = (req: Request, res: Response): boolean => {
if (!req.body || typeof req.body !== 'object') {