feat(admin): add admin settings panel for OIDC configuration
- Admin UI at /admin.html with settings management interface - REST API: GET/PUT /api/admin/settings/oidc, POST .../test, GET .../general - DB-backed settings in auth.admin_settings table (PostgreSQL) - OIDC auto-discovery from issuer URL (.well-known/openid-configuration) - Hot-reload: OIDC config changes apply without server restart - Role-based access: admin-only endpoints with 403 for regular users - Client secret stored securely, never exposed in GET responses - Env var override detection shown in admin UI - Clean architecture: repository trait, PG implementation, service, handler
This commit is contained in:
@@ -7,4 +7,5 @@ pub mod folder_repository;
|
||||
pub mod session_repository;
|
||||
pub mod share_repository;
|
||||
pub mod trash_repository;
|
||||
pub mod settings_repository;
|
||||
pub mod user_repository;
|
||||
@@ -0,0 +1,27 @@
|
||||
use std::collections::HashMap;
|
||||
use async_trait::async_trait;
|
||||
use crate::common::errors::DomainError;
|
||||
|
||||
/// Repository for platform settings stored in the database.
|
||||
/// Settings are key-value pairs organized by category (e.g., "oidc", "general").
|
||||
#[async_trait]
|
||||
pub trait SettingsRepository: Send + Sync + 'static {
|
||||
/// Get a single setting value by key
|
||||
async fn get(&self, key: &str) -> Result<Option<String>, DomainError>;
|
||||
|
||||
/// Get all settings for a given category
|
||||
async fn get_by_category(&self, category: &str) -> Result<HashMap<String, String>, DomainError>;
|
||||
|
||||
/// Set a setting value (upsert)
|
||||
async fn set(
|
||||
&self,
|
||||
key: &str,
|
||||
value: &str,
|
||||
category: &str,
|
||||
is_secret: bool,
|
||||
updated_by: Option<&str>,
|
||||
) -> Result<(), DomainError>;
|
||||
|
||||
/// Delete a setting by key
|
||||
async fn delete(&self, key: &str) -> Result<(), DomainError>;
|
||||
}
|
||||
Reference in New Issue
Block a user