Admin page: tabs, Authentik/CMS status, role security fix, sessions, activity log and system status - #229
Merged
Conversation
…e Authentik groups Security: the Authentik group endpoints listed every group and accepted any group id, so a platform admin could add anyone (themselves included) to Authentik's own "authentik Admins" group, i.e. SSO superuser. Groups are now limited to those that grant a platform role (except "default") or cms-manager; add/remove look the group up and return 403 for anything else. Group-to-role normalisation is shared with the OIDC login path. Admin page: - /admin with tabs kept in the URL (?tab=...); /admin/roles redirects there - Users & roles: Authentik banner with a link to its admin UI, backed by a new GET /admin/authentik/status; explains a missing AUTHENTIK_TOKEN instead of rendering an empty table; columns show the role granted - Content: points to the Directus CMS (GET /admin/cms), lists what is edited there and who may edit it - Arraial and Your account moved to their own tabs, unchanged in behaviour - load failures now surface an error instead of being swallowed
…em status
Removing a role now takes effect: role removal also drops the role from the
user's stored scopes (unless another group still grants it), since a session
refresh reissues whatever is stored and those were only updated at sign-in.
- POST /admin/users/{id}/sign-out ends every session of a user
- user.last_login_at, set when a new session is created (not on refresh)
- admin_activity table + GET /admin/activity: role changes, sign-outs,
Arraial settings and resets. Names are copied into each entry and there
are no foreign keys, so the log outlives the accounts it mentions
- GET /admin/system: commit (GIT_COMMIT, now passed by the deploy workflow),
DB migration vs code head, enabled extensions, integrations on/off
- Admin page: Last sign-in column, "never signed in" filter, per-user sign
out, Activity and System tabs, links to other admin pages
- explicit None defaults on optional response fields; drop response_model where it duplicates the return annotation; Annotated Query params; USER_NOT_FOUND constant - one throwing call per pytest.raises block - tab arrow-key handling on the focusable tab buttons, not the tablist - guard against empty CMS / system status responses - success toast is an <output>; static banners drop the live-region role - pending state starts as "" so its string comparisons type-check
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Admin page
/admin, with tabs kept in the URL (?tab=…). The old/admin/rolesredirects here.AUTHENTIK_TOKENis missing it explains that instead of showing an empty table.managed-tables.txt) and who can edit (cms-manager).Backend
GET /admin/authentik/status,GET /admin/cms,POST /admin/users/{id}/sign-out,GET /admin/activity,GET /admin/system.d6f8b0c2e4a7: addsuser.last_login_at(set when a session is created, not on refresh) and anadmin_activitytable. Activity entries copy names in and have no foreign keys, so the log outlives the accounts it mentions.group_role_name).GIT_COMMITis passed by the deploy workflow throughcompose.prod.yml, so the System tab can show what's live.Known limits
if scopes and …inoidc.py). Someone removed from every role group keeps their old roles. This may be deliberate, as protection against a missing claim wiping everyone's roles, so it deserves its own decision.Deploy notes
api_nei_migratestep.authentik Admins,authentik Read-only,default) no longer appear in the table. That's intended; they're managed in Authentik.Tests
last_login_at). mypy is clean.npm run buildpasses.