1
0
mirror of https://github.com/go-gitea/gitea.git synced 2025-01-03 14:57:55 -05:00
Go to file
Marcell Mars a3881ffa3d
Enhancing Gitea OAuth2 Provider with Granular Scopes for Resource Access (#32573)
Resolve #31609

This PR was initiated following my personal research to find the
lightest possible Single Sign-On solution for self-hosted setups. The
existing solutions often seemed too enterprise-oriented, involving many
moving parts and services, demanding significant resources while
promising planetary-scale capabilities. Others were adequate in
supporting basic OAuth2 flows but lacked proper user management
features, such as a change password UI.

Gitea hits the sweet spot for me, provided it supports more granular
access permissions for resources under users who accept the OAuth2
application.

This PR aims to introduce granularity in handling user resources as
nonintrusively and simply as possible. It allows third parties to inform
users about their intent to not ask for the full access and instead
request a specific, reduced scope. If the provided scopes are **only**
the typical ones for OIDC/OAuth2—`openid`, `profile`, `email`, and
`groups`—everything remains unchanged (currently full access to user's
resources). Additionally, this PR supports processing scopes already
introduced with [personal
tokens](https://docs.gitea.com/development/oauth2-provider#scopes) (e.g.
`read:user`, `write:issue`, `read:group`, `write:repository`...)

Personal tokens define scopes around specific resources: user info,
repositories, issues, packages, organizations, notifications,
miscellaneous, admin, and activitypub, with access delineated by read
and/or write permissions.

The initial case I wanted to address was to have Gitea act as an OAuth2
Identity Provider. To achieve that, with this PR, I would only add
`openid public-only` to provide access token to the third party to
authenticate the Gitea's user but no further access to the API and users
resources.

Another example: if a third party wanted to interact solely with Issues,
it would need to add `read:user` (for authorization) and
`read:issue`/`write:issue` to manage Issues.

My approach is based on my understanding of how scopes can be utilized,
supported by examples like [Sample Use Cases: Scopes and
Claims](https://auth0.com/docs/get-started/apis/scopes/sample-use-cases-scopes-and-claims)
on auth0.com.

I renamed `CheckOAuthAccessToken` to `GetOAuthAccessTokenScopeAndUserID`
so now it returns AccessTokenScope and user's ID. In the case of
additional scopes in `userIDFromToken` the default `all` would be
reduced to whatever was asked via those scopes. The main difference is
the opportunity to reduce the permissions from `all`, as is currently
the case, to what is provided by the additional scopes described above.

Screenshots:

![Screenshot_20241121_121405](https://github.com/user-attachments/assets/29deaed7-4333-4b02-8898-b822e6f2463e)

![Screenshot_20241121_120211](https://github.com/user-attachments/assets/7a4a4ef7-409c-4116-9d5f-2fe00eb37167)

![Screenshot_20241121_120119](https://github.com/user-attachments/assets/aa52c1a2-212d-4e64-bcdf-7122cee49eb6)

![Screenshot_20241121_120018](https://github.com/user-attachments/assets/9eac318c-e381-4ea9-9e2c-3a3f60319e47)
---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2024-11-22 12:06:41 +08:00
.devcontainer bump to go 1.23 (#31855) 2024-09-10 02:23:07 +00:00
.gitea Update demo site location from try.gitea.io -> demo.gitea.com (#31054) 2024-05-27 15:05:12 +00:00
.github Improve testing and try to fix MySQL hanging (#32515) 2024-11-15 23:45:07 +08:00
assets Update go dependencies (#32389) 2024-10-31 12:05:54 +00:00
build refactor: remove redundant err declarations (#32381) 2024-10-30 19:36:24 +00:00
cmd Refactor LFS SSH and internal routers (#32473) 2024-11-12 02:38:22 +00:00
contrib Add gh-access-token flag into backport script (#32283) 2024-10-17 01:43:48 -04:00
custom/conf Add avif image file support (#32508) 2024-11-15 00:55:50 +00:00
docker Update README.md (#30856) 2024-05-03 23:53:18 -04:00
models Fix GetInactiveUsers (#32540) 2024-11-21 04:55:32 +00:00
modules disable gravatar in test (#32529) 2024-11-21 04:30:48 +00:00
options Enhancing Gitea OAuth2 Provider with Granular Scopes for Resource Access (#32573) 2024-11-22 12:06:41 +08:00
public Update JS and PY dependencies (#32388) 2024-10-31 04:19:15 +00:00
routers Enhancing Gitea OAuth2 Provider with Granular Scopes for Resource Access (#32573) 2024-11-22 12:06:41 +08:00
services Enhancing Gitea OAuth2 Provider with Granular Scopes for Resource Access (#32573) 2024-11-22 12:06:41 +08:00
snap Bump CI,Flake and Snap to Node 22 (#32487) 2024-11-13 21:39:55 +00:00
templates Enhancing Gitea OAuth2 Provider with Granular Scopes for Resource Access (#32573) 2024-11-22 12:06:41 +08:00
tests Enhancing Gitea OAuth2 Provider with Granular Scopes for Resource Access (#32573) 2024-11-22 12:06:41 +08:00
tools Add lint-go-gopls (#30729) 2024-06-05 09:22:38 +08:00
web_src Fix PR diff review form submit (#32596) 2024-11-21 14:09:16 +00:00
.air.toml Reduce air verbosity (#31417) 2024-06-19 19:42:06 +00:00
.changelog.yml Adapt .changelog.yml to new labeling system (#27701) 2023-10-20 00:22:00 +02:00
.dockerignore Add /public/assets/img/webpack to ignore files again (#30451) 2024-04-13 04:28:20 +02:00
.editorconfig Add markdownlint (#20512) 2022-07-28 09:22:47 +08:00
.envrc Enable direnv (#31672) 2024-07-23 12:07:41 +00:00
.eslintrc.yaml Fix some typescript issues (#32586) 2024-11-21 13:57:42 +00:00
.gitattributes Add interface{} to any replacement to make fmt, exclude *.pb.go (#30461) 2024-04-13 17:32:15 +00:00
.gitignore Enable direnv (#31672) 2024-07-23 12:07:41 +00:00
.gitpod.yml Remove sqlite-viewer and using database client (#31223) 2024-06-03 10:41:29 +00:00
.golangci.yml Enable unparam linter (#31277) 2024-06-11 18:47:45 +00:00
.ignore Add /options/license and /options/gitignore to .ignore (#30219) 2024-03-31 22:22:29 +02:00
.markdownlint.yaml Enable markdownlint no-trailing-punctuation and no-blanks-blockquote (#29214) 2024-02-17 13:18:05 +00:00
.npmrc Upgrade to npm lockfile v3 and explicitely set it (#23561) 2023-03-18 19:38:10 +01:00
.spectral.yaml Add spectral linter for Swagger (#20321) 2022-07-11 18:07:16 -05:00
.yamllint.yaml fully replace drone with actions (#27556) 2023-10-11 06:39:32 +00:00
BSDmakefile Fix build errors on BSD (in BSDMakefile) (#27594) 2023-10-13 15:38:27 +00:00
build.go User/Org Feed render description as per web (#23887) 2023-04-04 04:39:47 +01:00
CHANGELOG-archived.md Fix changelog (main) (#30582) 2024-04-19 06:08:30 +00:00
CHANGELOG.md Fix changelog (main) (#30582) 2024-04-19 06:08:30 +00:00
CODE_OF_CONDUCT.md Add Gitea Community Code of Conduct (#23188) 2023-03-09 10:49:34 +08:00
CONTRIBUTING.md Have new announcement about docs contributions (#31364) 2024-06-14 11:17:05 +08:00
crowdin.yml Use Crowdin action for translation sync (#30054) 2024-03-30 18:11:50 +00:00
DCO Remove address from DCO (#22595) 2023-01-24 18:52:38 +00:00
Dockerfile bump to go 1.23 (#31855) 2024-09-10 02:23:07 +00:00
Dockerfile.rootless bump to go 1.23 (#31855) 2024-09-10 02:23:07 +00:00
flake.lock Bump CI,Flake and Snap to Node 22 (#32487) 2024-11-13 21:39:55 +00:00
flake.nix Fix a compilation error in the Gitpod environment (#32559) 2024-11-19 14:57:55 +08:00
go.mod Fix LFS route mock, realm, middleware names (#32488) 2024-11-13 16:58:09 +08:00
go.sum Update github.com/meilisearch/meilisearch-go (#32484) 2024-11-12 15:55:01 -05:00
LICENSE Fix typo 2016-11-08 08:42:05 +01:00
main.go Add some tests to clarify the "must-change-password" behavior (#30693) 2024-04-27 12:23:37 +00:00
MAINTAINERS Add bohde as maintainer (#31601) 2024-07-10 08:18:35 +08:00
Makefile add {{TEST_MINIO_ENDPOINT}} for local testing "with/without" docker + fix pgsql testing doc (#32105) 2024-10-03 01:00:56 +00:00
package-lock.json Update JS and PY dependencies (#32482) 2024-11-12 21:03:22 +00:00
package.json Update JS and PY dependencies (#32482) 2024-11-12 21:03:22 +00:00
playwright.config.ts Add initial typescript config and use it for eslint,vitest,playwright (#31186) 2024-06-28 16:15:51 +00:00
poetry.lock Update JS and PY dependencies (#32482) 2024-11-12 21:03:22 +00:00
poetry.toml Clean up pyproject.toml and package.json, fix poetry options (#25327) 2023-06-18 18:13:08 +00:00
pyproject.toml Update JS and PY dependencies (#32482) 2024-11-12 21:03:22 +00:00
README_ZH.md README Badge maintenance (#31441) 2024-06-21 13:18:39 +00:00
README.md README Badge maintenance (#31441) 2024-06-21 13:18:39 +00:00
SECURITY.md typo on date in security document (#31617) 2024-07-11 21:51:08 +00:00
stylelint.config.js Enable declaration-block-no-redundant-longhand-properties (#30950) 2024-05-12 02:33:05 +00:00
tailwind.config.js Add spacing to global error message (#31826) 2024-08-14 01:58:26 +00:00
tsconfig.json Move web globals to web_src/js/globals.d.ts (#31943) 2024-08-30 07:36:53 +00:00
updates.config.js Update JS dependencies (#31120) 2024-05-28 01:50:28 +00:00
vitest.config.ts Convert frontend code to typescript (#31559) 2024-07-07 15:32:30 +00:00
webpack.config.js Add back esbuild-loader for .js files (#31585) 2024-07-09 09:28:43 +00:00

Gitea

Contribute with Gitpod

View this document in Chinese

Purpose

The goal of this project is to make the easiest, fastest, and most painless way of setting up a self-hosted Git service.

As Gitea is written in Go, it works across all the platforms and architectures that are supported by Go, including Linux, macOS, and Windows on x86, amd64, ARM and PowerPC architectures. This project has been forked from Gogs since November of 2016, but a lot has changed.

For online demonstrations, you can visit demo.gitea.com.

For accessing free Gitea service (with a limited number of repositories), you can visit gitea.com.

To quickly deploy your own dedicated Gitea instance on Gitea Cloud, you can start a free trial at cloud.gitea.com.

Building

From the root of the source tree, run:

TAGS="bindata" make build

or if SQLite support is required:

TAGS="bindata sqlite sqlite_unlock_notify" make build

The build target is split into two sub-targets:

  • make backend which requires Go Stable, the required version is defined in go.mod.
  • make frontend which requires Node.js LTS or greater.

Internet connectivity is required to download the go and npm modules. When building from the official source tarballs which include pre-built frontend files, the frontend target will not be triggered, making it possible to build without Node.js.

More info: https://docs.gitea.com/installation/install-from-source

Using

./gitea web

Note

If you're interested in using our APIs, we have experimental support with documentation.

Contributing

Expected workflow is: Fork -> Patch -> Push -> Pull Request

Note

  1. YOU MUST READ THE CONTRIBUTORS GUIDE BEFORE STARTING TO WORK ON A PULL REQUEST.
  2. If you have found a vulnerability in the project, please write privately to security@gitea.io. Thanks!

Translating

Translations are done through Crowdin. If you want to translate to a new language ask one of the managers in the Crowdin project to add a new language there.

You can also just create an issue for adding a language or ask on discord on the #translation channel. If you need context or find some translation issues, you can leave a comment on the string or ask on Discord. For general translation questions there is a section in the docs. Currently a bit empty but we hope to fill it as questions pop up.

https://docs.gitea.com/contributing/localization

Crowdin

Further information

For more information and instructions about how to install Gitea, please look at our documentation. If you have questions that are not covered by the documentation, you can get in contact with us on our Discord server or create a post in the discourse forum.

We maintain a list of Gitea-related projects at gitea/awesome-gitea.

The official Gitea CLI is developed at gitea/tea.

Authors

Backers

Thank you to all our backers! 🙏 [Become a backer]

Sponsors

Support this project by becoming a sponsor. Your logo will show up here with a link to your website. [Become a sponsor]

FAQ

How do you pronounce Gitea?

Gitea is pronounced /ɡɪti:/ as in "gi-tea" with a hard g.

Why is this not hosted on a Gitea instance?

We're working on it.

License

This project is licensed under the MIT License. See the LICENSE file for the full license text.

Screenshots

Looking for an overview of the interface? Check it out!

Dashboard User Profile Global Issues
Branches Web Editor Activity
New Migration Migrating Pull Request View
Pull Request Dark Diff Review Dark Diff Dark