mirror of
https://github.com/volcengine/OpenViking.git
synced 2026-10-01 01:38:07 +08:00
* feat: support oidc and ldap auth * feat: support oidc and ldap auth * fix: remove heima partner, clean up auth docs, add web-studio unsupported auth banner - Remove heima from partner list in README (en/zh/ja) - Remove unsupported env var references (OPENVIKING_AUTH_MODE, OPENVIKING_USERNAME, OPENVIKING_PASSWORD) from LDAP auth docs - Remove temporary switch bash snippets from auth docs - Fix ldap_password description - Add web-studio unsupported-auth-mode banner for oidc/ldap servers * fix: address OIDC/LDAP review comments on auth plugin design Key changes driven by PR review: - **Role mapping**: OIDC and LDAP external identities always resolve to USER role. Removed map_role() calls and group_membership-based role mapping. Admin access is gated by the root API key mechanism only. - **LDAP credential extraction**: Removed query-parameter-based username/ password extraction (security concern — passwords in URLs can leak via shell history, proxy logs, and monitoring). Clients must use Basic Auth header or form data. - **OIDC identifier sanitization**: Auth0 and other providers may include characters like "|" in the `sub` claim. These are now replaced with "_" to produce valid OpenViking user identifiers. - **Dead code removal**: Removed _extract_groups, memberof_attribute, require_root_api_key_for_admin, _initialize_api_key_manager, and get_request_context_checks from both plugins since they are no longer needed. - **Docs**: Removed query-parameter curl example, memberof_attribute and require_root_api_key_for_admin config references. Co-authored-by: TRAE CLI <noreply@bytedance.com> * feat: support oidc and ldap auth * feat: support oidc and ldap auth * fix(auth): bind lazy OIDC imports at module scope --------- Co-authored-by: TRAE CLI <noreply@bytedance.com> Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>