Add external IdP authentication via OAuth (GitHub) and OIDC (Google, Azure AD). Users can sign in with enterprise credentials; accounts are auto-provisioned and linked on first login. Configured entirely via environment variables. - schema/011_external_auth.sql: user_identities table + email column on users - internal/auth/idp/: provider interface, GitHub OAuth, generic OIDC, store, handlers (list providers, login redirect, callback with auto-provisioning) - internal/auth/user_store.go: GetUserByEmail + SetEmail for IdP linking - cmd/synapbus/main.go: wire IdP routes + agent provisioner adapter - web/src/routes/login/+page.svelte: IdP buttons above password form - Tests: domain restriction, store CRUD, provider listing, user provisioning Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
24 lines
903 B
SQL
24 lines
903 B
SQL
-- External identity provider support (GitHub, Google, Azure AD)
|
|
-- Links external IdP accounts to local SynapBus users
|
|
|
|
CREATE TABLE IF NOT EXISTS user_identities (
|
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
user_id INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
|
|
provider TEXT NOT NULL,
|
|
external_id TEXT NOT NULL,
|
|
email TEXT,
|
|
display_name TEXT,
|
|
raw_claims TEXT NOT NULL DEFAULT '{}',
|
|
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
|
updated_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
|
UNIQUE(provider, external_id)
|
|
);
|
|
|
|
CREATE INDEX IF NOT EXISTS idx_user_identities_user ON user_identities(user_id);
|
|
CREATE INDEX IF NOT EXISTS idx_user_identities_lookup ON user_identities(provider, external_id);
|
|
|
|
-- Add email column to users table for IdP linking
|
|
ALTER TABLE users ADD COLUMN email TEXT;
|
|
|
|
INSERT INTO schema_migrations (version) VALUES (11);
|