all lists on lists.proxmox.com
 help / color / mirror / Atom feed
From: Azharul Haque <haque@azharul.com>
To: pve-devel@lists.proxmox.com
Cc: haque@azharul.com
Subject: [PATCH 0/3] ui: implement OpenID Connect login flow for #4281
Date: Mon, 10 Aug 2026 01:39:38 -0400	[thread overview]
Message-ID: <20260810053941.17000-1-haque@azharul.com> (raw)

The native Flutter "Proxmox VE Companion" app never implemented OpenID
Connect / OAuth realm login (bug #4281[0]): selecting an OAuth realm
just showed username/password fields that could never work.

This series adds the login-form side of OIDC support:

  - hide username/password fields for OpenID realms and drive the
    OAuth flow via flutter_web_auth_2 (system browser /
    ASWebAuthenticationSession on iOS, Chrome Custom Tabs on
    Android -- deliberately not an in-app webview)
  - fix a stale Continue button enabled/disabled state when switching
    realms mid-flow
  - namespace the OpenID redirect scheme under Proxmox's own reserved
    com.proxmox.* package prefix, to avoid custom-URL-scheme
    collisions with other apps on Android

Depends on the `type` property added to PveAccessDomainModel in the
companion proxmox_dart_api_client series. A further companion series
to pve_flutter_frontend registers the Android-side callback activity
for the scheme used here; no iOS-side wiring is required, since
ASWebAuthenticationSession resolves the custom-scheme redirect at
runtime without a static declaration.

Verified end-to-end against a real PVE server with an Authentik OIDC
realm, on both Android and iOS.

[0] https://bugzilla.proxmox.com/show_bug.cgi?id=4281

Azharul Haque (3):
  fix #4281: ui: add OpenID Connect login flow to login form
  fix #4281: ui: fix stale Continue button state on realm switch
  fix #4281: ui: use a namespaced OpenID callback scheme

 lib/proxmox_login_form.dart | 451 ++++++++++++++++++++++++------------
 pubspec.lock                | 160 +++++++++++--
 pubspec.yaml                |   1 +
 3 files changed, 441 insertions(+), 171 deletions(-)

-- 
2.50.1 (Apple Git-155)




             reply	other threads:[~2026-08-10 12:36 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-10  5:39 Azharul Haque [this message]
2026-08-10  5:39 ` [PATCH 1/3] fix #4281: ui: add OpenID Connect login flow to login form Azharul Haque
2026-08-10  5:39 ` [PATCH 2/3] fix #4281: ui: fix stale Continue button state on realm switch Azharul Haque
2026-08-10  5:39 ` [PATCH 3/3] fix #4281: ui: use a namespaced OpenID callback scheme Azharul Haque

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260810053941.17000-1-haque@azharul.com \
    --to=haque@azharul.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal