1#!/usr/bin/env python3
2"""Configure Shale guest login using an existing provider registration.
3
4Register a GitHub OAuth App at https://github.com/settings/developers with homepage
5https://shale.paperclover.net and callback
6https://snowglobe.paperclover.net/auth/guest/callback/github.
7For Astheno Identity, register a confidential OpenID Connect client with callback
8https://snowglobe.paperclover.net/auth/guest/callback/astheno and openid/profile scopes.
9GitHub requests only read:user. Neither provider grants repository access.
10
11Run: python3 tools/guest-provider.py github --client-id CLIENT_ID
12The secret is read with a hidden prompt and passed over SSH stdin, never in argv.
13Disable: python3 tools/guest-provider.py github --disable
14"""
15import argparse
16import getpass
17import json
18import os
19import subprocess
20
21parser = argparse.ArgumentParser(description=__doc__, formatter_class=argparse.RawDescriptionHelpFormatter)
22parser.add_argument('provider', choices=['github', 'astheno'])
23parser.add_argument('--client-id')
24parser.add_argument('--disable', action='store_true')
25parser.add_argument('--host', default=os.environ.get('STUDIO_DEPLOY_HOST', 'root@zenith'))
26parser.add_argument('--port', default=os.environ.get('STUDIO_DEPLOY_PORT', '22'))
27args = parser.parse_args()
28if not args.disable and not args.client_id:
29 parser.error('--client-id is required unless --disable is used')
30payload = {'provider': args.provider, 'enabled': not args.disable}
31if not args.disable:
32 payload.update(clientId=args.client_id, clientSecret=getpass.getpass('Client secret: '))
33result = subprocess.run(['ssh', '-p', args.port, args.host,
34 'podman exec -i studio-dashboard /bin/home-dashboard --guest-provider'],
35 input=json.dumps(payload), text=True, capture_output=True)
36if result.returncode:
37 raise SystemExit('Provider configuration did not complete. Check the dashboard and SSH connection.')
38print(result.stdout.strip())