feat(opsserver-admin): add persisted admin bootstrap flow with optional idp.global authentication
This commit is contained in:
@@ -1,6 +1,18 @@
|
||||
import * as plugins from '../plugins.js';
|
||||
import * as authInterfaces from '../data/auth.js';
|
||||
|
||||
export type TAdminLoginAuthSource = 'auto' | 'local' | 'idp.global';
|
||||
|
||||
export interface IAdminUserProjection {
|
||||
id: string;
|
||||
username: string;
|
||||
email?: string;
|
||||
name?: string;
|
||||
role: string;
|
||||
status?: 'active' | 'disabled';
|
||||
authSources?: Array<'local' | 'idp.global'>;
|
||||
}
|
||||
|
||||
// Admin Login
|
||||
export interface IReq_AdminLoginWithUsernameAndPassword extends plugins.typedrequestInterfaces.implementsTR<
|
||||
plugins.typedrequestInterfaces.ITypedRequest,
|
||||
@@ -10,12 +22,50 @@ export interface IReq_AdminLoginWithUsernameAndPassword extends plugins.typedreq
|
||||
request: {
|
||||
username: string;
|
||||
password: string;
|
||||
authSource?: TAdminLoginAuthSource;
|
||||
};
|
||||
response: {
|
||||
identity?: authInterfaces.IIdentity;
|
||||
};
|
||||
}
|
||||
|
||||
// Admin bootstrap status
|
||||
export interface IReq_GetAdminBootstrapStatus extends plugins.typedrequestInterfaces.implementsTR<
|
||||
plugins.typedrequestInterfaces.ITypedRequest,
|
||||
IReq_GetAdminBootstrapStatus
|
||||
> {
|
||||
method: 'getAdminBootstrapStatus';
|
||||
request: {};
|
||||
response: {
|
||||
dbEnabled: boolean;
|
||||
dbReady: boolean;
|
||||
hasPersistentAdmin: boolean;
|
||||
needsBootstrap: boolean;
|
||||
ephemeralAdminAvailable: boolean;
|
||||
idpGlobalConfigured: boolean;
|
||||
};
|
||||
}
|
||||
|
||||
// Create the first persisted admin account. Requires the bootstrap/ephemeral admin identity.
|
||||
export interface IReq_CreateInitialAdminUser extends plugins.typedrequestInterfaces.implementsTR<
|
||||
plugins.typedrequestInterfaces.ITypedRequest,
|
||||
IReq_CreateInitialAdminUser
|
||||
> {
|
||||
method: 'createInitialAdminUser';
|
||||
request: {
|
||||
identity: authInterfaces.IIdentity;
|
||||
email: string;
|
||||
name?: string;
|
||||
password: string;
|
||||
enableIdpGlobalAuth?: boolean;
|
||||
};
|
||||
response: {
|
||||
success: boolean;
|
||||
identity?: authInterfaces.IIdentity;
|
||||
user?: IAdminUserProjection;
|
||||
};
|
||||
}
|
||||
|
||||
// Admin Logout
|
||||
export interface IReq_AdminLogout extends plugins.typedrequestInterfaces.implementsTR<
|
||||
plugins.typedrequestInterfaces.ITypedRequest,
|
||||
@@ -43,4 +93,4 @@ export interface IReq_VerifyIdentity extends plugins.typedrequestInterfaces.impl
|
||||
valid: boolean;
|
||||
identity?: authInterfaces.IIdentity;
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user