Repository navigation
[FEATURE] Non-label based access control #356
Description
Activity
Hello,
While this would solve the issue it would break the project's base idea, (quoted from the documentation):
I am planning to keep the app in this state while slowly adding QOL updates. I am not planning to add any fancy dashboards or configuration files since I do not want to change the project's base idea.
One way to configure ACLs would be with environment variables/CLI flags (e.g.
ACLS_FOO_CONFIG_DOMAIN) but I am not very sure if it would be that user friendly.I would also love to see a similar feature - using TinyAuth to protect all my apps is my goal. I'd be ok with environment variables/CLI flags, since it would eliminate having to create an external configuration file - I don't think it's too alien a concept for users who would be needing such a feature.
Reacted by Kristófer Reykjalín, Ismael and NEANC.or.HZCK+1
Would also love the ability for Tinyauth to support authentication to different apps based on profiles/groups.I'm also using the binary, not docker, and would appreciate a way to configure access controls without docker labels.
but I am not very sure if it would be that user friendly
I would also be ok with configuring with environment variables/CLI flags, and there's already a precedence for it with the multiple OAuth providers feature you recently added for v4.
Reacted by NEANC.or.HZCKI don't use docker labels or caddy-docker-proxy. I use normal Caddy with a Caddyfile and I am wanting to allow a n8n instance to perform an API call on another service that is protected by TinyAuth. I am not sure how to allow this and can't find anything in the documentation to help.
This would be a great feature allowing for more varied usecases. Might I ask why you are against using a config file? I think if done in a similar fashion to traefik (where you can enable a file provider) it would be pretty intuitive.
Alright, let's add a simple yaml config file for storing ACLs. I will mark this issue as pinned so as it won't be closed by the stale bot.
Reacted by raghuscsa316Reacted by IsmaelAdded in #422! You will be able to use
TINYAUTH_APPS_WHATEVER_FOO=BARto configure ACLs using environment variables (and hopefully CLI flags)!Reacted by rinseaid and Andrew Kingston
Is your feature request related to a problem? Please describe.
Access controls and other per-app features are seemingly only available via docker labels. But some of the apps I host are not docker containers, and some are on other machines. This makes it impossible to set up custom access control for them.
Describe the solution you'd like
There must be a way to do this without docker labels. Access control features should be set up in tinyauth's own config only. Perhaps a sensible solution is creating profiles. They would be used via their uri path.
Example profiles.json:
After mounting profiles.json in tinyauth it would let me use these profiles in caddyfile: