Browse Source

docs(admin): remove readonly role references

codex/admin-oidc-auth-ui
Copilot 1 week ago
parent
commit
763ccf031e
  1. 4
      weed/admin/README.md
  2. 7
      weed/command/scaffold/security.toml

4
weed/admin/README.md

@ -172,7 +172,7 @@ redirect_url = "https://admin.example.com/login/oidc/callback"
scopes = ["openid", "profile", "email"] scopes = ["openid", "profile", "email"]
[admin.oidc.role_mapping] [admin.oidc.role_mapping]
default_role = "readonly"
default_role = "admin"
[[admin.oidc.role_mapping.rules]] [[admin.oidc.role_mapping.rules]]
claim = "groups" claim = "groups"
@ -180,7 +180,7 @@ value = "seaweedfs-admin"
role = "admin" role = "admin"
``` ```
Role mapping must resolve to either `admin` or `readonly`.
Role mapping must resolve to `admin`.
OIDC sessions are capped to the ID token expiration time. OIDC sessions are capped to the ID token expiration time.
### Docker Usage ### Docker Usage

7
weed/command/scaffold/security.toml

@ -180,18 +180,13 @@ tls_ca_cert = "" # optional absolute path for custom CA bundle
tls_insecure_skip_verify = false # testing only; do not use in production tls_insecure_skip_verify = false # testing only; do not use in production
[admin.oidc.role_mapping] [admin.oidc.role_mapping]
default_role = "readonly"
default_role = "admin"
[[admin.oidc.role_mapping.rules]] [[admin.oidc.role_mapping.rules]]
claim = "groups" claim = "groups"
value = "seaweedfs-admin" value = "seaweedfs-admin"
role = "admin" role = "admin"
[[admin.oidc.role_mapping.rules]]
claim = "groups"
value = "seaweedfs-readonly"
role = "readonly"
# white list. It's checking request ip address. # white list. It's checking request ip address.
[guard] [guard]
white_list = "" white_list = ""
Loading…
Cancel
Save