Skip to content

feat(oidc): add login templates for interactive and headless login - #25

Merged
jmgilman merged 6 commits into
masterfrom
feat/login-templates
Jul 3, 2026
Merged

jmgilman merged 6 commits into
masterfrom
feat/login-templates

Conversation

@jmgilman

@jmgilman jmgilman commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

Summary

First beyond-parity feature: login templates — named principals {name, subject, claims} declared in the JSON config (loginTemplates, global scope, config-only):

  • Interactive: the login page gains a Template dropdown (rendered only when templates exist) that pre-fills the username/claims fields; both stay editable before Sign-in.
  • Headless: login_hint=<template-name> on GET /{issuer}/authorize resolves the template and issues the code immediately — bypassing the login page even under interactiveLogin: true or prompt=login. Built for automated suites running the container with a mounted config.json; login_hint is a standard OIDC param, so off-the-shelf client libraries need no custom code.
  • Fail loudly: while templates are configured, an unknown hint is a hard invalid_request (redirected into a usable redirect_uri, else the direct error page). With no templates, login_hint stays ignored (current behavior).

Template claims resolve to an ordinary LoginSubmission, so they inherit the existing login-claims merge semantics (putIfAbsent at mint; callbacks/registered claims win).

Design/decision record: session 004 journal (journal/jmgilman).

Implementation

  • internal/oidc/logintemplate.go — LoginTemplate + ordered unique-name LoginTemplates collection; AuthorizeService gains a WithLoginTemplates option and the hint branch (after the response_type check, before interactive/prompt).
  • internal/oidc/httpapi — login_hint on both authorize ops; Deps.LoginTemplates; dropdown + 10-line inline pre-fill script in login.html (attribute-escaped claims JSON, no template.JS).
  • internal/config — loginTemplates parsing with index-tagged fail-fast validation (blank name/subject, duplicate names abort startup).
  • OpenAPI regenerated; docs: new how-to, configuration reference entry, Beyond-parity note, README bullet.

Testing

  • Unit/edge: domain hint matrix (precedence, unknown-hint error, no-templates fallthrough), template collection invariants, dropdown render + headless bypass + both error surfaces + form_post combination, config negatives. mise x -- moon run check green (incl. openapi drift-guard).
  • Container: new TestContainerLoginTemplates e2e (dropdown, headless flow verified against served JWKS, loud unknown-hint error); full integration suite green against mock-oidc:dev.
  • Manual DoD against the image with a Docker-mounted config: headless curl flow returned sub=alice + template claims in the id_token; unknown hint errored; browser check (chrome-devtools) confirmed dropdown pre-fill, editability, and "— none —" leaving fields untouched.
  • Webtest: two new automated checks + dropdown coverage in the manual login check.

🤖 Generated with Claude Code

jmgilman added 6 commits July 3, 2026 12:12
…anch

Named config-declared principals resolve headlessly via login_hint: a
matching template wins over interactiveLogin/prompt=login; an unknown
name is a hard invalid_request while templates are configured.
login_hint rides both authorize operations into the domain decode; the
login page offers configured templates as an editable pre-fill dropdown
(attribute-escaped claims JSON, no template.JS), gated off when empty.
…tion root

loginTemplates entries map through the domain constructors (index-tagged
fail-fast errors); buildWiring hands the collection to the
AuthorizeService and the login page. OpenAPI regenerated for login_hint.
… suites

Container e2e: dropdown rendered, headless login_hint flow with template
identity verified against the served JWKS, unknown hint errors loudly.
Webtest: two automated checks + dropdown pre-fill in the manual login check.
…parity

New how-to (config + Docker mount + dropdown + headless login_hint),
loginTemplates in the configuration reference, a Beyond parity note, nav
entry, README feature bullet and doc link.
@jmgilman
jmgilman merged commit 7c976bd into master Jul 3, 2026
13 checks passed
@jmgilman
jmgilman deleted the feat/login-templates branch July 3, 2026 19:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant