oidc.html 8.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205
  1. <form action="/_api/admin/security/passport-oidc" method="post" class="form-horizontal passportStrategy" id="oidcSetting" role="form"
  2. {% if isRestartingServerNeeded %}style="opacity: 0.4;"{% endif %}>
  3. <legend class="alert-anchor">{{ t("security_setting.OAuth.OIDC.name") }} {{ t("security_setting.configuration") }}</legend>
  4. {% set nameForIsOIDCEnabled = "settingForm[security:passport-oidc:isEnabled]" %}
  5. {% set isOidcEnabled = settingForm['security:passport-oidc:isEnabled'] %}
  6. {% set siteUrl = getConfig('crowi', 'app:siteUrl') || '[INVALID]' %}
  7. {% set callbackUrl = siteUrl + '/passport/oidc/callback' %}
  8. <div class="form-group">
  9. <label for="{{nameForIsOIDCEnabled}}" class="col-xs-3 control-label">{{ t("security_setting.OAuth.OIDC.name") }}</label>
  10. <div class="col-xs-6">
  11. <div class="btn-group btn-toggle" data-toggle="buttons">
  12. <label class="btn btn-default btn-rounded btn-outline {% if isOidcEnabled %}active{% endif %}" data-active-class="primary">
  13. <input name="{{nameForIsOIDCEnabled}}" value="true" type="radio"
  14. {% if true === isOidcEnabled %}checked{% endif %}> ON
  15. </label>
  16. <label class="btn btn-default btn-rounded btn-outline {% if !isOidcEnabled %}active{% endif %}" data-active-class="default">
  17. <input name="{{nameForIsOIDCEnabled}}" value="false" type="radio"
  18. {% if !isOidcEnabled %}checked{% endif %}> OFF
  19. </label>
  20. </div>
  21. </div>
  22. </div>
  23. <fieldset id="passport-oidc-hide-when-disabled" {%if !isOidcEnabled %}style="display: none;"{% endif %}>
  24. <div class="form-group">
  25. <label for="settingForm[security:passport-oidc:providerName]" class="col-xs-3 control-label">{{ t("security_setting.providerName") }}</label>
  26. <div class="col-xs-6">
  27. <input class="form-control" type="text" name="settingForm[security:passport-oidc:providerName]" value="{{ settingForm['security:passport-oidc:providerName'] || '' }}">
  28. </div>
  29. </div>
  30. <div class="form-group">
  31. <label for="settingForm[security:passport-oidc:issuerHost]" class="col-xs-3 control-label">{{ t("security_setting.issuerHost") }}</label>
  32. <div class="col-xs-6">
  33. <input class="form-control" type="text" name="settingForm[security:passport-oidc:issuerHost]" value="{{ settingForm['security:passport-oidc:issuerHost'] || '' }}">
  34. <p class="help-block">
  35. <small>
  36. {{ t("security_setting.Use env var if empty", "OAUTH_OIDC_ISSUER_HOST") }}
  37. </small>
  38. </p>
  39. </div>
  40. </div>
  41. <div class="form-group">
  42. <label for="settingForm[security:passport-oidc:clientId]" class="col-xs-3 control-label">{{ t("security_setting.clientID") }}</label>
  43. <div class="col-xs-6">
  44. <input class="form-control" type="text" name="settingForm[security:passport-oidc:clientId]" value="{{ settingForm['security:passport-oidc:clientId'] || '' }}">
  45. <p class="help-block">
  46. <small>
  47. {{ t("security_setting.Use env var if empty", "OAUTH_OIDC_CLIENT_ID") }}
  48. </small>
  49. </p>
  50. </div>
  51. </div>
  52. <div class="form-group">
  53. <label for="settingForm[security:passport-oidc:clientSecret]" class="col-xs-3 control-label">{{ t("security_setting.client_secret") }}</label>
  54. <div class="col-xs-6">
  55. <input class="form-control" type="text" name="settingForm[security:passport-oidc:clientSecret]" value="{{ settingForm['security:passport-oidc:clientSecret'] || '' }}">
  56. <p class="help-block">
  57. <small>
  58. {{ t("security_setting.Use env var if empty", "OAUTH_OIDC_CLIENT_SECRET") }}
  59. </small>
  60. </p>
  61. </div>
  62. </div>
  63. <h4>Attribute Mapping ({{ t("security_setting.optional") }})</h4>
  64. <div class="form-group">
  65. <label for="settingForm[security:passport-oidc:attrMapId]" class="col-xs-3 control-label">Identifier</label>
  66. <div class="col-xs-6">
  67. <input class="form-control" type="text" name="settingForm[security:passport-oidc:attrMapId]" value="{{ settingForm['security:passport-oidc:attrMapId'] || '' }}">
  68. <p class="help-block">
  69. <small>
  70. {{ t("security_setting.OAuth.OIDC.id_detail") }}
  71. </small>
  72. </p>
  73. </div>
  74. </div>
  75. <div class="form-group">
  76. <label for="settingForm[security:passport-oidc:attrMapUserName]" class="col-xs-3 control-label">Username</label>
  77. <div class="col-xs-6">
  78. <input class="form-control" type="text" name="settingForm[security:passport-oidc:attrMapUserName]" value="{{ settingForm['security:passport-oidc:attrMapUserName'] || '' }}">
  79. <p class="help-block">
  80. <small>
  81. {{ t("security_setting.OIDC.username_detail") }}
  82. </small>
  83. </p>
  84. </div>
  85. </div>
  86. <div class="form-group">
  87. <label for="settingForm[security:passport-oidc:attrMapName]" class="col-xs-3 control-label">Name</label>
  88. <div class="col-xs-6">
  89. <input class="form-control" type="text" name="settingForm[security:passport-oidc:attrMapName]" value="{{ settingForm['security:passport-oidc:attrName'] || '' }}">
  90. <p class="help-block">
  91. <small>
  92. {{ t("security_setting.OIDC.name_detail") }}
  93. </small>
  94. </p>
  95. </div>
  96. </div>
  97. <div class="form-group">
  98. <label for="settingForm[security:passport-oidc:attrMapMail]" class="col-xs-3 control-label">Mail</label>
  99. <div class="col-xs-6">
  100. <input class="form-control" type="text" name="settingForm[security:passport-oidc:attrMapMail]" value="{{ settingForm['security:passport-oidc:attrMapMail'] || '' }}">
  101. <p class="help-block">
  102. <small>
  103. {{ t("security_setting.OIDC.mapping_detail", t("Email")) }}
  104. </small>
  105. </p>
  106. </div>
  107. </div>
  108. <div class="form-group">
  109. <label class="col-xs-3 control-label">{{ t("security_setting.callback_URL") }}</label>
  110. <div class="col-xs-6">
  111. <input class="form-control" type="text" value="{{ callbackUrl }}" readonly>
  112. <p class="help-block small">{{ t("security_setting.desc_of_callback_URL", 'OAuth') }}</p>
  113. {% if !getConfig('crowi', 'app:siteUrl') %}
  114. <div class="alert alert-danger">
  115. <i class="icon-exclamation"></i> {{ t("security_setting.alert_siteUrl_is_not_set", '<a href="/admin/app">' + t('App settings') + '<i class="icon-login"></i></a>') }}
  116. </div>
  117. {% endif %}
  118. </div>
  119. </div>
  120. <div class="form-group">
  121. <div class="col-xs-6 col-xs-offset-3">
  122. <div class="checkbox checkbox-info">
  123. <input type="checkbox" id="bindByUserName-oidc" name="settingForm[security:passport-oidc:isSameUsernameTreatedAsIdenticalUser]" value="1"
  124. {% if settingForm['security:passport-oidc:isSameUsernameTreatedAsIdenticalUser'] %}checked{% endif %} />
  125. <label for="bindByUserName-oidc">
  126. {{ t("security_setting.Treat username matching as identical", "username") }}
  127. </label>
  128. <p class="help-block">
  129. <small>
  130. {{ t("security_setting.Treat username matching as identical_warn", "username") }}
  131. </small>
  132. </p>
  133. </div>
  134. </div>
  135. </div>
  136. <div class="form-group">
  137. <div class="col-xs-6 col-xs-offset-3">
  138. <div class="checkbox checkbox-info">
  139. <input type="checkbox" id="bindByEmail-oidc" name="settingForm[security:passport-oidc:isSameEmailTreatedAsIdenticalUser]" value="1"
  140. {% if settingForm['security:passport-oidc:isSameEmailTreatedAsIdenticalUser'] %}checked{% endif %} />
  141. <label for="bindByEmail-oidc">
  142. {{ t("security_setting.Treat email matching as identical", "email") }}
  143. </label>
  144. <p class="help-block">
  145. <small>
  146. {{ t("security_setting.Treat email matching as identical_warn", "email") }}
  147. </small>
  148. </p>
  149. </div>
  150. </div>
  151. </div>
  152. </fieldset>
  153. <div class="form-group" id="btn-update">
  154. <div class="col-xs-offset-3 col-xs-6">
  155. <input type="hidden" name="_csrf" value="{{ csrf() }}">
  156. <button type="submit" class="btn btn-primary">{{ t('Update') }}</button>
  157. </div>
  158. </div>
  159. </form>
  160. {# Help Section #}
  161. <hr>
  162. <div style="min-height: 300px;">
  163. <h4>
  164. <i class="icon-question" aria-hidden="true"></i>
  165. <a href="#collapseHelpForOidcOauth" data-toggle="collapse">{{ t("security_setting.OAuth.how_to.oidc") }}</a>
  166. </h4>
  167. <ol id="collapseHelpForOidcOauth" class="collapse">
  168. <li>{{ t("security_setting.OAuth.OIDC.register_1") }}</li>
  169. <li>{{ t("security_setting.OAuth.OIDC.register_2", callbackUrl) }}</li>
  170. <li>{{ t("security_setting.OAuth.OIDC.register_3") }}</li>
  171. </ol>
  172. </div>
  173. <script>
  174. $('input[name="settingForm[security:passport-oidc:isEnabled]"]').change(function() {
  175. const isEnabled = ($(this).val() === "true");
  176. if (isEnabled) {
  177. $('#passport-oidc-hide-when-disabled').show(400);
  178. }
  179. else {
  180. $('#passport-oidc-hide-when-disabled').hide(400);
  181. }
  182. });
  183. </script>