feat: enterprise identity provider support — GitHub, Google, Azure AD login
Add external IdP authentication via OAuth (GitHub) and OIDC (Google, Azure AD). Users can sign in with enterprise credentials; accounts are auto-provisioned and linked on first login. Configured entirely via environment variables. - schema/011_external_auth.sql: user_identities table + email column on users - internal/auth/idp/: provider interface, GitHub OAuth, generic OIDC, store, handlers (list providers, login redirect, callback with auto-provisioning) - internal/auth/user_store.go: GetUserByEmail + SetEmail for IdP linking - cmd/synapbus/main.go: wire IdP routes + agent provisioner adapter - web/src/routes/login/+page.svelte: IdP buttons above password form - Tests: domain restriction, store CRUD, provider listing, user provisioning Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
bd166843d6
commit
87f24afd58
@@ -0,0 +1,23 @@
|
||||
-- External identity provider support (GitHub, Google, Azure AD)
|
||||
-- Links external IdP accounts to local SynapBus users
|
||||
|
||||
CREATE TABLE IF NOT EXISTS user_identities (
|
||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||
user_id INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
|
||||
provider TEXT NOT NULL,
|
||||
external_id TEXT NOT NULL,
|
||||
email TEXT,
|
||||
display_name TEXT,
|
||||
raw_claims TEXT NOT NULL DEFAULT '{}',
|
||||
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
||||
updated_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
||||
UNIQUE(provider, external_id)
|
||||
);
|
||||
|
||||
CREATE INDEX IF NOT EXISTS idx_user_identities_user ON user_identities(user_id);
|
||||
CREATE INDEX IF NOT EXISTS idx_user_identities_lookup ON user_identities(provider, external_id);
|
||||
|
||||
-- Add email column to users table for IdP linking
|
||||
ALTER TABLE users ADD COLUMN email TEXT;
|
||||
|
||||
INSERT INTO schema_migrations (version) VALUES (11);
|
||||
Reference in New Issue
Block a user