| 1 | #!/usr/bin/env python3 |
| 2 | """Configure Shale guest login using an existing provider registration. |
| 3 | |
| 4 | Register a GitHub OAuth App at https://github.com/settings/developers with homepage |
| 5 | https://shale.paperclover.net and callback |
| 6 | https://snowglobe.paperclover.net/auth/guest/callback/github. |
| 7 | For Astheno Identity, register a confidential OpenID Connect client with callback |
| 8 | https://snowglobe.paperclover.net/auth/guest/callback/astheno and openid/profile scopes. |
| 9 | GitHub requests only read:user. Neither provider grants repository access. |
| 10 | |
| 11 | Run: python3 tools/guest-provider.py github --client-id CLIENT_ID |
| 12 | The secret is read with a hidden prompt and passed over SSH stdin, never in argv. |
| 13 | Disable: python3 tools/guest-provider.py github --disable |
| 14 | """ |
| 15 | import argparse |
| 16 | import getpass |
| 17 | import json |
| 18 | import os |
| 19 | import subprocess |
| 20 | |
| 21 | parser = argparse.ArgumentParser(description=__doc__, formatter_class=argparse.RawDescriptionHelpFormatter) |
| 22 | parser.add_argument('provider', choices=['github', 'astheno']) |
| 23 | parser.add_argument('--client-id') |
| 24 | parser.add_argument('--disable', action='store_true') |
| 25 | parser.add_argument('--host', default=os.environ.get('STUDIO_DEPLOY_HOST', 'root@zenith')) |
| 26 | parser.add_argument('--port', default=os.environ.get('STUDIO_DEPLOY_PORT', '22')) |
| 27 | args = parser.parse_args() |
| 28 | if not args.disable and not args.client_id: |
| 29 | parser.error('--client-id is required unless --disable is used') |
| 30 | payload = {'provider': args.provider, 'enabled': not args.disable} |
| 31 | if not args.disable: |
| 32 | payload.update(clientId=args.client_id, clientSecret=getpass.getpass('Client secret: ')) |
| 33 | result = subprocess.run(['ssh', '-p', args.port, args.host, |
| 34 | 'podman exec -i studio-dashboard /bin/home-dashboard --guest-provider'], |
| 35 | input=json.dumps(payload), text=True, capture_output=True) |
| 36 | if result.returncode: |
| 37 | raise SystemExit('Provider configuration did not complete. Check the dashboard and SSH connection.') |
| 38 | print(result.stdout.strip()) |