Skip to content

feat(oauth2): restrict OAUTH2 Console to configured groups (default deny) - #165

Open
romanetar wants to merge 2 commits into
mainfrom
feat/oauth-console-group-gate
Open

romanetar wants to merge 2 commits into
mainfrom
feat/oauth-console-group-gate

Conversation

@romanetar

@romanetar romanetar commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Prevents non-privileged users from creating OAuth apps (ClickUp 86bca26y2).

  • New env var OAUTH2_CONSOLE_ALLOWED_GROUPS (comma-separated group slugs), loaded in config/oauth2.php as console_allowed_groups.
  • User::canAccessOAuth2Console(): true only for members of a configured group. Empty/missing config = nobody has access. No bypass for super admins.
  • New middlewares oauth2.console.access (404, web) and oauth2.console.access.json (403, API).
  • Gated routes: /admin/clients, /admin/clients/edit/{id}, /admin/grants and the whole /admin/api/v1/clients* group (so apps can't be created via API either).
  • "OAUTH2 Console" menu hidden in the Blade menu and the React navbar/drawer (menuConfig.canAccessOAuth2Console).

Deployment note

Set OAUTH2_CONSOLE_ALLOWED_GROUPS in every environment. Without it nobody can access the console (intentional). Requires yarn build for the React menu.

Testing

  • tests/OAuth2ConsoleAccessTest.php (DB-free): 5 tests, passing.
  • tests/OAuth2ConsoleRoutesTest.php (routes, real middleware stack): 6 tests / 48 assertions, passing locally (web 404, API 403, no super-admin bypass, member access, menu flag).
  • Manual test plan: empty config → no menu and 404/403 for everyone (incl. super admin); configured group → members get access, non-members don't.

Summary by CodeRabbit

  • New Features
    • OAuth2 Console access can now be restricted to members of configured groups. An empty group setting allows no one to access the console.
    • The console menu and navigation options are shown only to users with access.
  • Access Control
    • Users without access are blocked from console pages and API actions; page requests return a not-found response, while API requests return a forbidden response.

…eny)

Add OAUTH2_CONSOLE_ALLOWED_GROUPS (comma separated group slugs, loaded via
config/oauth2.php). Only members of those groups see the OAUTH2 Console menu
and can use /admin/clients, /admin/grants and /admin/api/v1/clients*. When the
setting is empty or missing nobody has access; super admins get no bypass.
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 5d1a6817-c1cd-4d7a-b940-1db33e03d5b7

✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

📘 OpenAPI / Swagger preview

➡️ https://OpenStackweb.github.io/openstackid/openapi/pr-165/

This page is automatically updated on each push to this PR.

Disable the ssl redirect that masked gate responses, hydrate fresh user
entities from the DB, and add users to the group before authenticating.
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

📘 OpenAPI / Swagger preview

➡️ https://OpenStackweb.github.io/openstackid/openapi/pr-165/

This page is automatically updated on each push to this PR.

@romanetar
romanetar requested a review from smarcet October 2, 2026 13:55

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant