X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/0099f77a806d38ff1f7bd1c2b45da2bdec4c89ec..ef9107221d53f19bf848d3dca0b570f468519550:/lib/config/config.default.yml diff --git a/lib/config/config.default.yml b/lib/config/config.default.yml index 52856c8438..81c36b9bfb 100644 --- a/lib/config/config.default.yml +++ b/lib/config/config.default.yml @@ -493,8 +493,29 @@ Clusters: Login: # These settings are provided by your OAuth2 provider (eg # Google) used to perform upstream authentication. - ProviderAppSecret: "" ProviderAppID: "" + ProviderAppSecret: "" + + # (Experimental) Authenticate with Google, bypassing the + # SSO-provider gateway service. Use the Google Cloud console to + # enable the People API (APIs and Services > Enable APIs and + # services > Google People API > Enable), generate a Client ID + # and secret (APIs and Services > Credentials > Create + # credentials > OAuth client ID > Web application) and add your + # controller's /login URL (e.g., + # "https://zzzzz.example.com/login") as an authorized redirect + # URL. + # + # Requires EnableBetaController14287. ProviderAppID must be + # blank. + GoogleClientID: "" + GoogleClientSecret: "" + + # Allow users to log in to existing accounts using any verified + # email address listed by their Google account. If true, the + # Google People API must be enabled in order for Google login to + # work. If false, only the primary email address will be used. + GoogleAlternateEmailAddresses: true # The cluster ID to delegate the user database. When set, # logins on this cluster will be redirected to the login cluster @@ -1060,7 +1081,7 @@ Clusters: # Workbench welcome screen, this is HTML text that will be # incorporated directly onto the page. WelcomePageHTML: | - +

Please log in.

The "Log in" button below will show you a sign-in @@ -1075,5 +1096,12 @@ Clusters: identification, and does not retrieve any other personal information. + InactivePageHTML: | + +

Hi! You're logged in, but...

+

Your account is inactive.

+

An administrator must activate your account before you can get + any further.

+ # Use experimental controller code (see https://dev.arvados.org/issues/14287) EnableBetaController14287: false