Skip to content

SSO: each UM server as its own OAuth endpoint + recipe SSO schema #33

Description

@halfcyan

Part of the Ultramarine Server roadmap (Outline: Server):

dashboard has integrated SSO for apps — see what apps we can define oauth through quadlets (nextcloud, portainer, that kinda thing)

Goal

Every UM server acts as its own OAuth/OIDC endpoint, so apps on the server can offer SSO without depending on a central service. Tetra is the natural home for the endpoint: it runs on the server, holds identity, and already terminates authenticated connections. The dashboard (centrally hosted, or local on the server) manages clients and consumes the metadata.

This issue is part design, part implementation. The exact shape of the endpoint needs settling before code.

Tasks

  • Design: how tetra serves an OAuth/OIDC endpoint (discovery, authorize, token, userinfo), and what the identity source is (dashboard users? host users? both?)
  • Implement the endpoint behind a feature flag
  • Recipe schema: optional SSO/OAuth section so recipes declare support (provider hints, redirect URIs, scopes)
  • Validate the section; surface through recipes.context so templates can consume it; expose SSO capability per app
  • Reference example using the Nextcloud recipe in examples/
  • Docs: docs/recipes.md, docs/agent-protocol.md
  • Tests

Dashboard consumer tracked in Ultramarine-Linux/dashboard#7.

Related: #29 (per-app SSO capability surfaces through the apps module).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions