Skip to content

config: only require the OIDC client secret for serve - #229

Closed
joshsol1 wants to merge 1 commit into
sol1:mainfrom
joshsol1:main
Closed

joshsol1 wants to merge 1 commit into
sol1:mainfrom
joshsol1:main

Conversation

@joshsol1

@joshsol1 joshsol1 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Config::load exited with [oidc] is configured but no client_secret was provided for every subcommand, including add-admin, list-admins and map-group. That secret lives in /opt/rustguac/env, which only systemd's EnvironmentFile= loads, so running the admin CLI from a shell failed until the secret was also in the config.toml file.

This change keeps the OIDC_CLIENT_SECRET override in Config::load, but moves the presence check into a new Config::validate_oidc_secret() that returns a Result, and calls it only on the serve path. Admin subcommands only touch the SQLite database and never contact the IdP, so they no longer need the secret.

Changes

  • src/config.rs: Config::load no longer exits on a missing OIDC secret; new validate_oidc_secret() carries the same operator-facing message. Four unit tests added.
  • src/main.rs: serve runs the validation before starting; other subcommands skip it.

Testing

Built an unpatched and a patched binary and ran both against a throwaway config with an [oidc] block and no client_secret:

Scenario Before After
add-admin, no secret in env exit 1 with the error admin created
list-admins, no secret in env exit 1 with the error lists admins
serve, no secret exit 1 with the error exit 1 with the error (unchanged)
serve, secret sourced from env file starts starts

Also cargo fmt --check, cargo clippy -- -D warnings and cargo test (310 passed) are clean.

`Config::load` exited with "[oidc] is configured but no client_secret
was provided" for every subcommand, including `add-admin`. The secret
normally lives in /opt/rustguac/env, which only systemd's
EnvironmentFile loads, so running the admin CLI from an interactive
shell on a freshly installed host failed unless the secret was also
copied into config.toml, which defeats the point of the env file.

Keep the OIDC_CLIENT_SECRET override in `Config::load`, but move the
presence check into `Config::validate_oidc_secret` and call it only on
the `serve` path. Admin subcommands touch just the SQLite database and
never contact the IdP. Add unit tests for the validation function.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@joshsol1 joshsol1 closed this Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant