feat: v6.7.0 — SSO/SAML + OIDC entreprise (SP SAML signé + OIDC PKCE, auto-provisioning, groupes IdP → rôles workspace, SSO only, onglet Settings « SSO / Enterprise », API /api/v2/sso/*, help, migration 23, docs + OpenAPI 439 chemins) · 802 tests verts
FlowDeck CI / lint (push) Successful in 1m28s
FlowDeck CI / test (push) Successful in 11m52s
FlowDeck CI / docker (push) Successful in 1m51s

This commit is contained in:
2026-09-24 13:32:17 -04:00
parent 9562f30366
commit d074689b18
25 changed files with 4507 additions and 31 deletions
+504 -2
View File
@@ -2,7 +2,7 @@
"openapi": "3.1.0",
"info": {
"title": "FlowDeck",
"version": "6.6.0"
"version": "6.7.0"
},
"paths": {
"/auth/register": {
@@ -161,7 +161,7 @@
"auth"
],
"summary": "Logout",
"description": "Clear session and redirect to login page.",
"description": "Clear session and redirect to login page.\n\nSAML sessions additionally hand over to the IdP's Single Logout when one\nis configured (the actual cookie clearing happens on the SLO route).",
"operationId": "logout_auth_logout_get",
"responses": {
"200": {
@@ -195,6 +195,508 @@
}
}
},
"/auth/saml/login": {
"get": {
"tags": [
"sso"
],
"summary": "Saml Login",
"description": "SP-initiated SSO: issue an AuthnRequest and redirect to the IdP.",
"operationId": "saml_login_auth_saml_login_get",
"parameters": [
{
"name": "next",
"in": "query",
"required": false,
"schema": {
"type": "string",
"default": "/workspaces",
"title": "Next"
}
}
],
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
},
"422": {
"description": "Validation Error",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/HTTPValidationError"
}
}
}
}
}
}
},
"/auth/saml/callback": {
"post": {
"tags": [
"sso"
],
"summary": "Saml Callback",
"description": "Assertion Consumer Service — validate the SAMLResponse and open a session.",
"operationId": "saml_callback_auth_saml_callback_post",
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
}
}
}
},
"/auth/saml/metadata": {
"get": {
"tags": [
"sso"
],
"summary": "Saml Metadata",
"description": "SP metadata XML — paste into the IdP (Azure AD / Okta / Keycloak…).",
"operationId": "saml_metadata_auth_saml_metadata_get",
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
}
}
}
},
"/auth/saml/logout": {
"get": {
"tags": [
"sso"
],
"summary": "Saml Logout",
"description": "SP-initiated Single Logout (GET) — hands the browser to the IdP.",
"operationId": "saml_logout_auth_saml_logout_get",
"parameters": [
{
"name": "next",
"in": "query",
"required": false,
"schema": {
"type": "string",
"default": "/auth/login?provider=local",
"title": "Next"
}
}
],
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
},
"422": {
"description": "Validation Error",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/HTTPValidationError"
}
}
}
}
}
},
"post": {
"tags": [
"sso"
],
"summary": "Saml Logout Post",
"description": "IdP-initiated Single Logout (POST with SAMLRequest/SAMLResponse).",
"operationId": "saml_logout_post_auth_saml_logout_post",
"parameters": [
{
"name": "next",
"in": "query",
"required": false,
"schema": {
"type": "string",
"default": "/auth/login?provider=local",
"title": "Next"
}
}
],
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
},
"422": {
"description": "Validation Error",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/HTTPValidationError"
}
}
}
}
}
}
},
"/auth/oidc/login": {
"get": {
"tags": [
"sso"
],
"summary": "Oidc Login",
"description": "Redirect to the OIDC provider (authorization code + PKCE).",
"operationId": "oidc_login_auth_oidc_login_get",
"parameters": [
{
"name": "next",
"in": "query",
"required": false,
"schema": {
"type": "string",
"default": "/workspaces",
"title": "Next"
}
}
],
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
},
"422": {
"description": "Validation Error",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/HTTPValidationError"
}
}
}
}
}
}
},
"/auth/oidc/callback": {
"get": {
"tags": [
"sso"
],
"summary": "Oidc Callback",
"description": "OIDC callback (GET, authorization code in the query string).",
"operationId": "oidc_callback_auth_oidc_callback_get",
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
}
}
},
"post": {
"tags": [
"sso"
],
"summary": "Oidc Callback Post",
"description": "OIDC callback (POST, form_post response mode).",
"operationId": "oidc_callback_post_auth_oidc_callback_post",
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
}
}
}
},
"/auth/oidc/logout": {
"get": {
"tags": [
"sso"
],
"summary": "Oidc Logout",
"description": "OIDC logout (GET) — local session first, then the IdP end-session URL.",
"operationId": "oidc_logout_auth_oidc_logout_get",
"parameters": [
{
"name": "next",
"in": "query",
"required": false,
"schema": {
"type": "string",
"default": "/auth/login?provider=local",
"title": "Next"
}
}
],
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
},
"422": {
"description": "Validation Error",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/HTTPValidationError"
}
}
}
}
}
},
"post": {
"tags": [
"sso"
],
"summary": "Oidc Logout Post",
"description": "OIDC logout (POST).",
"operationId": "oidc_logout_post_auth_oidc_logout_post",
"parameters": [
{
"name": "next",
"in": "query",
"required": false,
"schema": {
"type": "string",
"default": "/auth/login?provider=local",
"title": "Next"
}
}
],
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
},
"422": {
"description": "Validation Error",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/HTTPValidationError"
}
}
}
}
}
}
},
"/api/v2/sso/providers": {
"get": {
"tags": [
"sso"
],
"summary": "Sso Providers",
"description": "Public: what the login page should show (button list + sso_only flag).",
"operationId": "sso_providers_api_v2_sso_providers_get",
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
}
}
}
},
"/api/v2/sso/config": {
"get": {
"tags": [
"sso"
],
"summary": "Get Sso Config Api",
"description": "Read the current SSO configuration (secrets never returned).",
"operationId": "get_sso_config_api_api_v2_sso_config_get",
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
}
}
},
"put": {
"tags": [
"sso"
],
"summary": "Save Sso Config Api",
"description": "Create/replace the SSO configuration (admin, scope write).",
"operationId": "save_sso_config_api_api_v2_sso_config_put",
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
}
}
},
"post": {
"tags": [
"sso"
],
"summary": "Save Sso Config Api",
"description": "Create/replace the SSO configuration (admin, scope write).",
"operationId": "save_sso_config_api_api_v2_sso_config_post",
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
}
}
},
"delete": {
"tags": [
"sso"
],
"summary": "Delete Sso Config Api",
"description": "Disable SSO — local logins keep working (design §8 « SSO disable »).",
"operationId": "delete_sso_config_api_api_v2_sso_config_delete",
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
}
}
}
},
"/api/v2/sso/workspaces": {
"get": {
"tags": [
"sso"
],
"summary": "Sso Workspaces",
"description": "Workspaces available for default assignment / group mapping.",
"operationId": "sso_workspaces_api_v2_sso_workspaces_get",
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
}
}
}
},
"/api/v2/sso/sync": {
"post": {
"tags": [
"sso"
],
"summary": "Sso Sync",
"description": "Re-apply group → workspace role mapping for every SSO user.",
"operationId": "sso_sync_api_v2_sso_sync_post",
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
}
}
}
},
"/api/v2/sso/history": {
"get": {
"tags": [
"sso"
],
"summary": "Sso History",
"description": "Audit trail of SSO login attempts (successes and rejections).",
"operationId": "sso_history_api_v2_sso_history_get",
"parameters": [
{
"name": "limit",
"in": "query",
"required": false,
"schema": {
"type": "integer",
"default": 50,
"title": "Limit"
}
}
],
"responses": {
"200": {
"description": "Successful Response",
"content": {
"application/json": {
"schema": {}
}
}
},
"422": {
"description": "Validation Error",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/HTTPValidationError"
}
}
}
}
}
}
},
"/trash": {
"get": {
"tags": [