mirror of
https://github.com/go-gitea/gitea.git
synced 2026-08-16 00:35:10 +00:00
chore: Pre-register a builtin OAuth2 application for the official Gitea mobile app (#38880) (#38922)
Backport #38880 by @lunny This is a prepare and required step for upcoming Gitea Official Mobile APP which supports login with OAuth2. Gitea already pre-registers OAuth2 applications for a few universally useful clients (`git-credential-oauth`, Git Credential Manager and `tea`), so those tools can run an Authorization Code + PKCE login against any instance without the user having to create an OAuth application by hand. The official Gitea mobile app needs the same mechanism. This adds a builtin application for it: | | | |---|---| | client ID | `b757811a-05c8-4c76-8d74-a5ee3d2073f2` | | config name | `gitea-app` | | display name | `Gitea App` | | redirect URI | `com.gitea.app://oauth/callback` | Unlike the existing entries, which are CLIs and can therefore use a loopback `http://127.0.0.1` redirect, a mobile app authorises through a system browser session (`ASWebAuthenticationSession` on iOS, Custom Tabs on Android) that can only receive a custom-scheme callback, hence the custom scheme here. Notes: * Builtin applications are inserted directly by `auth.Init`, so they do not pass through `DetectInvalidOAuth2ApplicationRedirectURI`, which is only applied to user- and API-created applications. No `[oauth2] CUSTOM_SCHEMES` configuration is required for this to work, and `ContainsRedirectURI` matches the URI by normalised string comparison. * Instances that do not want the application pre-registered can drop `gitea-app` from `[oauth2] DEFAULT_APPLICATIONS`, exactly as with the existing entries; `auth.Init` then deletes it again. * The client is public: no client secret, PKCE `S256` required. --- Generated by Codet Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
This commit is contained in:
@@ -606,7 +606,8 @@ ENABLED = true
|
|||||||
;; * https://github.com/hickford/git-credential-oauth
|
;; * https://github.com/hickford/git-credential-oauth
|
||||||
;; * https://github.com/git-ecosystem/git-credential-manager
|
;; * https://github.com/git-ecosystem/git-credential-manager
|
||||||
;; * https://gitea.com/gitea/tea
|
;; * https://gitea.com/gitea/tea
|
||||||
;DEFAULT_APPLICATIONS = git-credential-oauth, git-credential-manager, tea
|
;; * Gitea App (the official Gitea mobile app)
|
||||||
|
;DEFAULT_APPLICATIONS = git-credential-oauth, git-credential-manager, tea, gitea-app
|
||||||
;;
|
;;
|
||||||
;; By default, OAuth2 applications can only use "http" and "https" as their redirect URI schemes.
|
;; By default, OAuth2 applications can only use "http" and "https" as their redirect URI schemes.
|
||||||
;; If you need to use other schemes (e.g. for desktop applications), you can specify them here as a comma-separated list.
|
;; If you need to use other schemes (e.g. for desktop applications), you can specify them here as a comma-separated list.
|
||||||
|
|||||||
@@ -83,6 +83,11 @@ func BuiltinApplications() map[string]*BuiltinOAuth2Application {
|
|||||||
DisplayName: "tea",
|
DisplayName: "tea",
|
||||||
RedirectURIs: []string{"http://127.0.0.1", "https://127.0.0.1"},
|
RedirectURIs: []string{"http://127.0.0.1", "https://127.0.0.1"},
|
||||||
}
|
}
|
||||||
|
m["b757811a-05c8-4c76-8d74-a5ee3d2073f2"] = &BuiltinOAuth2Application{
|
||||||
|
ConfigName: "gitea-app",
|
||||||
|
DisplayName: "Gitea App",
|
||||||
|
RedirectURIs: []string{"com.gitea.app://oauth/callback"},
|
||||||
|
}
|
||||||
return m
|
return m
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -108,7 +108,7 @@ var OAuth2 = struct {
|
|||||||
JWTSigningAlgorithm: "RS256",
|
JWTSigningAlgorithm: "RS256",
|
||||||
JWTSigningPrivateKeyFile: "jwt/private.pem",
|
JWTSigningPrivateKeyFile: "jwt/private.pem",
|
||||||
MaxTokenLength: math.MaxInt16,
|
MaxTokenLength: math.MaxInt16,
|
||||||
DefaultApplications: []string{"git-credential-oauth", "git-credential-manager", "tea"},
|
DefaultApplications: []string{"git-credential-oauth", "git-credential-manager", "tea", "gitea-app"},
|
||||||
}
|
}
|
||||||
|
|
||||||
func loadOAuth2From(rootCfg ConfigProvider) {
|
func loadOAuth2From(rootCfg ConfigProvider) {
|
||||||
|
|||||||
@@ -62,7 +62,7 @@ func TestGetGeneralSigningSecretSave(t *testing.T) {
|
|||||||
func TestOauth2DefaultApplications(t *testing.T) {
|
func TestOauth2DefaultApplications(t *testing.T) {
|
||||||
cfg, _ := NewConfigProviderFromData(``)
|
cfg, _ := NewConfigProviderFromData(``)
|
||||||
loadOAuth2From(cfg)
|
loadOAuth2From(cfg)
|
||||||
assert.Equal(t, []string{"git-credential-oauth", "git-credential-manager", "tea"}, OAuth2.DefaultApplications)
|
assert.Equal(t, []string{"git-credential-oauth", "git-credential-manager", "tea", "gitea-app"}, OAuth2.DefaultApplications)
|
||||||
|
|
||||||
cfg, _ = NewConfigProviderFromData(`[oauth2]
|
cfg, _ = NewConfigProviderFromData(`[oauth2]
|
||||||
DEFAULT_APPLICATIONS = tea
|
DEFAULT_APPLICATIONS = tea
|
||||||
|
|||||||
Reference in New Issue
Block a user