feat(admin): add admin settings panel for OIDC configuration

- Admin UI at /admin.html with settings management interface
- REST API: GET/PUT /api/admin/settings/oidc, POST .../test, GET .../general
- DB-backed settings in auth.admin_settings table (PostgreSQL)
- OIDC auto-discovery from issuer URL (.well-known/openid-configuration)
- Hot-reload: OIDC config changes apply without server restart
- Role-based access: admin-only endpoints with 403 for regular users
- Client secret stored securely, never exposed in GET responses
- Env var override detection shown in admin UI
- Clean architecture: repository trait, PG implementation, service, handler
This commit is contained in:
Dionisio
2026-02-11 00:15:26 +01:00
parent 8ef62109a3
commit f60c0df9f9
16 changed files with 1048 additions and 23 deletions
+1
View File
@@ -7,4 +7,5 @@ pub mod folder_repository;
pub mod session_repository;
pub mod share_repository;
pub mod trash_repository;
pub mod settings_repository;
pub mod user_repository;
@@ -0,0 +1,27 @@
use std::collections::HashMap;
use async_trait::async_trait;
use crate::common::errors::DomainError;
/// Repository for platform settings stored in the database.
/// Settings are key-value pairs organized by category (e.g., "oidc", "general").
#[async_trait]
pub trait SettingsRepository: Send + Sync + 'static {
/// Get a single setting value by key
async fn get(&self, key: &str) -> Result<Option<String>, DomainError>;
/// Get all settings for a given category
async fn get_by_category(&self, category: &str) -> Result<HashMap<String, String>, DomainError>;
/// Set a setting value (upsert)
async fn set(
&self,
key: &str,
value: &str,
category: &str,
is_secret: bool,
updated_by: Option<&str>,
) -> Result<(), DomainError>;
/// Delete a setting by key
async fn delete(&self, key: &str) -> Result<(), DomainError>;
}