X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/9d2cf97c13005304f0a9031fd5d88ac89906bb33..4257184a0fd276af7e1741dda8a7468a30b4a9c6:/lib/config/generated_config.go diff --git a/lib/config/generated_config.go b/lib/config/generated_config.go index 42d94da786..ece3a627fd 100644 --- a/lib/config/generated_config.go +++ b/lib/config/generated_config.go @@ -281,6 +281,12 @@ Clusters: # in the directory where your API server is running. AnonymousUserToken: "" + # If a new user has an alternate email address (local@domain) + # with the domain given here, its local part becomes the new + # user's default username. Otherwise, the user's primary email + # address is used. + PreferDomainForUsername: "" + AuditLogs: # Time to keep audit logs, in seconds. (An audit log is a row added # to the "logs" table in the PostgreSQL database each time an @@ -499,12 +505,33 @@ Clusters: Login: # These settings are provided by your OAuth2 provider (eg # Google) used to perform upstream authentication. - ProviderAppSecret: "" ProviderAppID: "" + ProviderAppSecret: "" + + # (Experimental) Authenticate with Google, bypassing the + # SSO-provider gateway service. Use the Google Cloud console to + # enable the People API (APIs and Services > Enable APIs and + # services > Google People API > Enable), generate a Client ID + # and secret (APIs and Services > Credentials > Create + # credentials > OAuth client ID > Web application) and add your + # controller's /login URL (e.g., + # "https://zzzzz.example.com/login") as an authorized redirect + # URL. + # + # Requires EnableBetaController14287. ProviderAppID must be + # blank. + GoogleClientID: "" + GoogleClientSecret: "" + + # Allow users to log in to existing accounts using any verified + # email address listed by their Google account. If true, the + # Google People API must be enabled in order for Google login to + # work. If false, only the primary email address will be used. + GoogleAlternateEmailAddresses: true # The cluster ID to delegate the user database. When set, # logins on this cluster will be redirected to the login cluster - # (login cluster must appear in RemoteHosts with Proxy: true) + # (login cluster must appear in RemoteClusters with Proxy: true) LoginCluster: "" # How long a cached token belonging to a remote cluster will @@ -1066,8 +1093,7 @@ Clusters: # Workbench welcome screen, this is HTML text that will be # incorporated directly onto the page. WelcomePageHTML: | -
- +

Please log in.

The "Log in" button below will show you a sign-in @@ -1081,7 +1107,13 @@ Clusters: Arvados Workbench uses your name and email address only for identification, and does not retrieve any other personal information. -

+ + InactivePageHTML: | + +

Hi! You're logged in, but...

+

Your account is inactive.

+

An administrator must activate your account before you can get + any further.

# Use experimental controller code (see https://dev.arvados.org/issues/14287) EnableBetaController14287: false