Conversation
…eny) Add OAUTH2_CONSOLE_ALLOWED_GROUPS (comma separated group slugs, loaded via config/oauth2.php). Only members of those groups see the OAUTH2 Console menu and can use /admin/clients, /admin/grants and /admin/api/v1/clients*. When the setting is empty or missing nobody has access; super admins get no bypass.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
📘 OpenAPI / Swagger preview ➡️ https://OpenStackweb.github.io/openstackid/openapi/pr-165/ This page is automatically updated on each push to this PR. |
Disable the ssl redirect that masked gate responses, hydrate fresh user entities from the DB, and add users to the group before authenticating.
|
📘 OpenAPI / Swagger preview ➡️ https://OpenStackweb.github.io/openstackid/openapi/pr-165/ This page is automatically updated on each push to this PR. |
Summary
Prevents non-privileged users from creating OAuth apps (ClickUp 86bca26y2).
OAUTH2_CONSOLE_ALLOWED_GROUPS(comma-separated group slugs), loaded inconfig/oauth2.phpasconsole_allowed_groups.User::canAccessOAuth2Console(): true only for members of a configured group. Empty/missing config = nobody has access. No bypass for super admins.oauth2.console.access(404, web) andoauth2.console.access.json(403, API)./admin/clients,/admin/clients/edit/{id},/admin/grantsand the whole/admin/api/v1/clients*group (so apps can't be created via API either).menuConfig.canAccessOAuth2Console).Deployment note
Set
OAUTH2_CONSOLE_ALLOWED_GROUPSin every environment. Without it nobody can access the console (intentional). Requiresyarn buildfor the React menu.Testing
tests/OAuth2ConsoleAccessTest.php(DB-free): 5 tests, passing.tests/OAuth2ConsoleRoutesTest.php(routes, real middleware stack): 6 tests / 48 assertions, passing locally (web 404, API 403, no super-admin bypass, member access, menu flag).Summary by CodeRabbit