Conversation
`Config::load` exited with "[oidc] is configured but no client_secret was provided" for every subcommand, including `add-admin`. The secret normally lives in /opt/rustguac/env, which only systemd's EnvironmentFile loads, so running the admin CLI from an interactive shell on a freshly installed host failed unless the secret was also copied into config.toml, which defeats the point of the env file. Keep the OIDC_CLIENT_SECRET override in `Config::load`, but move the presence check into `Config::validate_oidc_secret` and call it only on the `serve` path. Admin subcommands touch just the SQLite database and never contact the IdP. Add unit tests for the validation function. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Config::loadexited with[oidc] is configured but no client_secret was providedfor every subcommand, includingadd-admin,list-adminsandmap-group. That secret lives in/opt/rustguac/env, which only systemd'sEnvironmentFile=loads, so running the admin CLI from a shell failed until the secret was also in theconfig.tomlfile.This change keeps the
OIDC_CLIENT_SECREToverride inConfig::load, but moves the presence check into a newConfig::validate_oidc_secret()that returns aResult, and calls it only on theservepath. Admin subcommands only touch the SQLite database and never contact the IdP, so they no longer need the secret.Changes
src/config.rs:Config::loadno longer exits on a missing OIDC secret; newvalidate_oidc_secret()carries the same operator-facing message. Four unit tests added.src/main.rs:serveruns the validation before starting; other subcommands skip it.Testing
Built an unpatched and a patched binary and ran both against a throwaway config with an
[oidc]block and noclient_secret:add-admin, no secret in envlist-admins, no secret in envserve, no secretserve, secret sourced from env fileAlso
cargo fmt --check,cargo clippy -- -D warningsandcargo test(310 passed) are clean.