feat: allow specifying callback port for OIDC auth
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 3/5
- Geschätzter Aufwand
- 1-2 Tage
- Anfängerfreundlichkeit
- 78/100
- Issue-Typ
- Feature
- Klarheit
- Klar beschrieben
- Aktivitätsstatus
- Aktiv
- Tech-Stack
- rust
- Bereich
- authentication, cli
Rechercherichtung
Beginne in crates/openshell-cli/src/oidc_auth.rs bei etwa den Zeilen 188–190 und verfolge, wie der Listener-Port die Konstruktion von redirect_uri erreicht. Aktualisiere docs/reference/gateway-auth.mdx bei etwa den Zeilen 92–98 und 123 und füge Unit-Tests für den konfigurierten Port sowie einen Bind-Kollisionsfehler hinzu. Die Aufgabe ist erledigt, wenn die Umgebungsvariable den Listener-Port auswählt, ungültige oder nicht verfügbare Ports aussagekräftige Fehler erzeugen und das standardmäßige Verhalten mit einem ephemeren Port unverändert bleibt.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
User Story
As an openshell consumer, I'd need the OIDC flow to work with a specific ephemeral port for SSO login. This is because the underlying auth0 provider does not allow regex on the port for allowed callback urls
Problem Statement
Provide a way to fix the CLI ephemeral callback port to a specific value so that it's easier to add the callback url
Impact / Why This Matters
Right now the SSO login requires whitelisting every possible ephemeral port in localhost which is not ideal.
Proposed Design
Provide the control of port via env variable OPENSHELL_OIDC_CALLBACK_PORT or something similar
Acceptance Criteria
- the callback port gets opened on specific port instead of any ephemeral port
Alternatives Considered
client credentials flow is what I am considering it for now
Agent Investigation
Spike Plan: feat: allow OIDC callback listener to bind a fixed port via env var
Scope decision: Env-var only (OPENSHELL_OIDC_CALLBACK_PORT) — no GatewayMetadata/clap changes.
Problem statement: The CLI's OIDC login flow binds an OS-assigned ephemeral port (127.0.0.1:0) for the local callback listener. Providers that require pre-registering exact redirect URIs can't reasonably whitelist the full ephemeral range, so login fails or requires impractical whitelisting.
Code changes (all in crates/openshell-cli/src/oidc_auth.rs):
- :188 — check OPENSHELL_OIDC_CALLBACK_PORT; if set, parse as u16 and bind that specific port with a wrapped, actionable error on bind failure; else keep current bind("127.0.0.1:0") behavior.
- No changes needed to redirect_uri construction (:189-190) or callback handling (:660-716) — they already work off whatever port the listener has.
Labels: area:cli, state:validated
Complexity: Low · Confidence: High · Est. files: 1 (+ docs, + tests)
Risks to include in the issue: - Bind-failure UX must give actionable guidance (today's raw OS error is not user-friendly).
- Fixed port is predictable, but existing CSRF state check + PKCE already prevent exploitation — mention, not a blocker.
- No interaction with token/mTLS storage or TUI (confirmed).
Docs impact: docs/reference/gateway-auth.mdx — add the new env var to the table (~line 92-98) and update prose at line 123.
Test additions: unit test setting the env var and asserting the bound port matches; a bind-collision test asserting the friendly error message.
Checklist
- I've reviewed existing issues and the architecture docs
- This is a design proposal, not a "please build this" request
- Vorherrschende Sprache
- Rust
- Sterne
- 15.4k
- Forks
- 1.7k
- Ø Merge
- 1 T. 21 Std.
- Gemergte PRs (30 T.)
- 366
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Hat eine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus NVIDIA/OpenShell
-
state:triage-needed
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
Maintainer antworten meist innerhalb von 1 Tag
-
docs: document workspace and provider label capabilitiesEvtl. vergeben @johntmyers hat das vor 3 Tagen übernommen. Offenarea:docs
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
NVIDIA/OpenShell#4250 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
bug(driver-mxc): test helper fails to compile after gateway-name argumentEvtl. vergeben @feloy hat das vor 5 Tagen übernommen. Offenstate:triage-needed
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 88/100
Maintainer antworten meist innerhalb von 1 Tag
-
bug: install.sh ignores XDG_CONFIG_HOME for the local gateway configEvtl. vergeben @fede-kamel hat das vor 9 Tagen übernommen. Offenarea:cli os:linux os:macos state:validated
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
NVIDIA/OpenShell#4042 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
state:triage-needed
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
NVIDIA/OpenShell#3995 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in NVIDIA/OpenShell
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
objectionary/sodg.rs#301 ·
-
[Bug] Completion info popup (.cm-completionInfo) ignores the configured editor fontEvtl. vergeben Ein verknüpfter Pull Request ist offen oder bereits gemergt. Offenbug user-priority/P2
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 62/100
t8y2/dbx#11718 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 65/100
rescript-lang/rescript#8765 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
nautechsystems/nautilus_trader#5287 ·
Maintainer antworten meist innerhalb von 1 Tag
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 62/100
farion1231/cc-switch#8072 ·
Maintainer antworten meist innerhalb von 1 Tag