Add Authentik SSO via OAuth2/OIDC

Implements Single Sign-On with Authentik alongside the existing
password login. Admins configure Client ID, Client Secret and Base URL
directly in the app; the SSO button on the login page only appears
when the configuration is complete and enabled.

- SsoSetting model + migration (one-row config table)
- sso_provider_id / is_sso_user fields on users (migration)
- SsoController: redirect to Authentik + callback (token exchange,
  userinfo fetch, auto-create unknown users)
- Admin\SsoSettingController + admin/sso/show view with setup guide
  and one-click Redirect URI copy
- Admin dropdown: SSO-Konfiguration entry
- Login page: Authentik button rendered conditionally

No additional Composer packages required.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Housemann
2026-06-13 15:13:30 +02:00
co-authored by Claude Sonnet 4.6
parent c5fe3ad808
commit 60259a3655
10 changed files with 507 additions and 1 deletions
+3
View File
@@ -471,6 +471,9 @@
<i class="fas fa-palette me-2"></i>Nagellacke</a></li>
<li><a class="dropdown-item" href="{{ route('admin.statistics') }}">
<i class="fas fa-chart-bar me-2"></i>Statistiken</a></li>
<li><hr class="dropdown-divider" style="border-color:rgba(255,255,255,0.1);"></li>
<li><a class="dropdown-item" href="{{ route('admin.sso.show') }}">
<i class="fas fa-shield-alt me-2"></i>SSO-Konfiguration</a></li>
</ul>
</li>
@endif