mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-12 19:57:37 +00:00
feat(sso): split SSO providers by delivery model across tiers (#754)
Custom OIDC stays on Community so self-hosters can wire any spec-compliant OIDC identity provider (Authelia, Keycloak, Authentik, Zitadel, and others). Google, GitHub, and Okta one-click presets move to Skipper. LDAP / Active Directory and scoped RBAC are Admiral-only. Backend enforces the split via a new requireTierForSsoProvider helper in middleware/tierGates.ts, applied after requireAdmin in all four ssoConfig mutation handlers. GET /sso/config (list) stays ungated so downgraded admins can still see previously-configured providers. Invalid provider ids now 400 before the tier check to avoid leaking tier information. Frontend adds a compact mode to PaidGate and AdmiralGate for inline list-item locks, and SSOSection reorders the provider cards as Custom OIDC > Google > GitHub > Okta > LDAP to reinforce the free-to-paid progression. Stale 'SSO is Admiral' copy in AdmiralGate, PaidGate, and the Admiral upgrade card on the License settings page has been replaced to reflect the new split. User-facing licensing, SSO, overview, quickstart, and security docs have been updated with the per-tier provider matrix.
This commit is contained in:
@@ -8,6 +8,8 @@ import { Badge } from '@/components/ui/badge';
|
||||
import { toast } from '@/components/ui/toast-store';
|
||||
import { apiFetch } from '@/lib/api';
|
||||
import { CapabilityGate } from './CapabilityGate';
|
||||
import { PaidGate } from './PaidGate';
|
||||
import { AdmiralGate } from './AdmiralGate';
|
||||
import { Loader2, CheckCircle, XCircle } from 'lucide-react';
|
||||
|
||||
const ROLE_OPTIONS = [
|
||||
@@ -42,12 +44,14 @@ interface SSOProviderConfig {
|
||||
oidcEmailClaim?: string;
|
||||
}
|
||||
|
||||
// Ordered by tier: Custom OIDC (Community) → preset OIDC (Skipper) → LDAP/AD (Admiral).
|
||||
// The ordering reinforces the free → paid progression in the UI.
|
||||
const PROVIDERS = [
|
||||
{ id: 'ldap', label: 'LDAP / Active Directory', type: 'ldap' as const },
|
||||
{ id: 'oidc_custom', label: 'Custom OIDC', type: 'oidc' as const },
|
||||
{ id: 'oidc_google', label: 'Google', type: 'oidc' as const },
|
||||
{ id: 'oidc_github', label: 'GitHub', type: 'oidc' as const },
|
||||
{ id: 'oidc_okta', label: 'Okta', type: 'oidc' as const },
|
||||
{ id: 'oidc_custom', label: 'Custom OIDC', type: 'oidc' as const },
|
||||
{ id: 'ldap', label: 'LDAP / Active Directory', type: 'ldap' as const },
|
||||
];
|
||||
|
||||
function ProviderCard({ providerId, type, label, initialConfig, onSave }: {
|
||||
@@ -379,6 +383,23 @@ function ProviderCard({ providerId, type, label, initialConfig, onSave }: {
|
||||
);
|
||||
}
|
||||
|
||||
// Mirrors the backend tier split in ssoConfig.ts requireTierForProvider: Custom OIDC
|
||||
// is free, preset OIDC (Google/GitHub/Okta) requires Skipper+, LDAP requires Admiral.
|
||||
function ProviderCardWithGate(props: {
|
||||
providerId: string;
|
||||
type: 'ldap' | 'oidc';
|
||||
label: string;
|
||||
initialConfig: SSOProviderConfig | null;
|
||||
onSave: () => void;
|
||||
}) {
|
||||
const card = <ProviderCard {...props} />;
|
||||
if (props.providerId === 'oidc_custom') return card;
|
||||
if (props.providerId === 'ldap') {
|
||||
return <AdmiralGate compact featureName="LDAP / Active Directory">{card}</AdmiralGate>;
|
||||
}
|
||||
return <PaidGate compact featureName={`${props.label} SSO`}>{card}</PaidGate>;
|
||||
}
|
||||
|
||||
export function SSOSection() {
|
||||
const [configs, setConfigs] = useState<SSOProviderConfig[]>([]);
|
||||
|
||||
@@ -399,7 +420,7 @@ export function SSOSection() {
|
||||
<div className="space-y-6">
|
||||
<div className="space-y-3">
|
||||
{PROVIDERS.map(p => (
|
||||
<ProviderCard
|
||||
<ProviderCardWithGate
|
||||
key={p.id}
|
||||
providerId={p.id}
|
||||
type={p.type}
|
||||
|
||||
Reference in New Issue
Block a user