mirror of
https://github.com/BookStackApp/BookStack.git
synced 2026-02-08 03:09:39 +03:00
Implement HD parameter for Google Socialite Login #2868
Closed
opened 2026-02-05 05:31:40 +03:00 by OVERLORD
·
6 comments
No Branch/Tag Specified
development
further_theme_development
l10n_development
release
llm_only
vectors
v25-11
docker_env
drawio_rendering
user_permissions
ldap_host_failover
svg_image
prosemirror
captcha_example
fix/video-export
v25.12.3
v25.12.2
v25.12.1
v25.12
v25.11.6
v25.11.5
v25.11.4
v24.11.4
v25.11.3
v25.11.2
v25.11.1
v25.11
v25.07.3
v25.07.2
v25.07.1
v25.07
v25.05.2
v25.05.1
v25.05
v25.02.5
v25.02.4
v25.02.3
v25.02.2
v25.02.1
v25.02
v24.12.1
v24.12
v24.10.3
v24.10.2
v24.10.1
v24.10
v24.05.4
v24.05.3
v24.05.2
v24.05.1
v24.05
v24.02.3
v24.02.2
v24.02.1
v24.02
v23.12.3
v23.12.2
v23.12.1
v23.12
v23.10.4
v23.10.3
v23.10.2
v23.10.1
v23.10
v23.08.3
v23.08.2
v23.08.1
v23.08
v23.06.2
v23.06.1
v23.06
v23.05.2
v23.05.1
v23.05
v23.02.3
v23.02.2
v23.02.1
v23.02
v23.01.1
v23.01
v22.11.1
v22.11
v22.10.2
v22.10.1
v22.10
v22.09.1
v22.09
v22.07.3
v22.07.2
v22.07.1
v22.07
v22.06.2
v22.06.1
v22.06
v22.04.2
v22.04.1
v22.04
v22.03.1
v22.03
v22.02.3
v22.02.2
v22.02.1
v22.02
v21.12.5
v21.12.4
v21.12.3
v21.12.2
v21.12.1
v21.12
v21.11.3
v21.11.2
v21.11.1
v21.11
v21.10.3
v21.10.2
v21.10.1
v21.10
v21.08.6
v21.08.5
v21.08.4
v21.08.3
v21.08.2
v21.08.1
v21.08
v21.05.4
v21.05.3
v21.05.2
v21.05.1
v21.05
v21.04.6
v21.04.5
v21.04.4
v21.04.3
v21.04.2
v21.04.1
v21.04
v0.31.8
v0.31.7
v0.31.6
v0.31.5
v0.31.4
v0.31.3
v0.31.2
v0.31.1
v0.31.0
v0.30.7
v0.30.6
v0.30.5
v0.30.4
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.2
v0.23.1
v0.23.0
v0.22.0
v0.21.0
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.5
v0.18.4
v0.18.3
v0.18.2
v0.18.1
v0.18.0
v0.17.4
v0.17.3
v0.17.2
v0.17.1
v0.17.0
v0.16.3
v0.16.2
v0.16.1
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.1
v0.13.0
v0.12.2
v0.12.1
v0.12.0
v0.11.2
v0.11.1
v0.11.0
v0.10.0
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.6
v0.7.5
v0.7.4
v0.7.3
0.7.2
v.0.7.1
v0.7.0
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.0
Labels
Clear labels
🎨 Design
📖 Docs Update
🐛 Bug
🐛 Bug
:cat2:🐈 Possible duplicate
💿 Database
☕ Open to discussion
💻 Front-End
🐕 Support
🚪 Authentication
🌍 Translations
🔌 API Task
🏭 Back-End
⛲ Upstream
🔨 Feature Request
🛠️ Enhancement
🛠️ Enhancement
🛠️ Enhancement
❤️ Happy feedback
🔒 Security
🔍 Pending Validation
💆 UX
📝 WYSIWYG Editor
🌔 Out of scope
🔩 API Request
:octocat: Admin/Meta
🖌️ View Customization
❓ Question
🚀 Priority
🛡️ Blocked
🚚 Export System
♿ A11y
🔧 Maintenance
> Markdown Editor
pull-request
Mirrored from GitHub Pull Request
No Label
🔨 Feature Request
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/BookStack#2868
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @LeafedFox on GitHub (Jun 22, 2022).
Describe the feature you'd like
Ability to specify a value for HD parameter for Google Login to restrict users to a Google Workspace organisation, e.g.
GOOGLE_HD=example.comin.envDescribe the benefits this would bring to existing BookStack users
Ability to utilise Google login whilst restricting to the internal organisation, without having to resort to setting up SAML
Can the goal of this request already be achieved via other means?
No
Have you searched for an existing open/closed issue?
How long have you been using BookStack?
Not using yet, just scoping
Additional context
No response
@ssddanbrown commented on GitHub (Jun 22, 2022):
Hi @ItsGageH,
It's not clear what
hdparameter this refers to. Google list ahdauthentication URI parameter in their OIDC docs, but not their standard OAuth docs which shares an endpoint (although we might be using an older endpoint). This documented parameter is stated to be a UI optimization only, not a way to control/verify workspace. There looks to be ahdparam provided in the id token for OIDC but it would require us to go out the way to verify that in our standard non-OIDC OAuth flow here.If it's going to be your primary auth method, with all users coming from your Google workspace, it might be worth using SAML or OIDC (If that allows the same control) in the long run for a smoother experience. I am surprised though that google does not offer you control to limit the OAuth app used for social login, to your workspace as required.
As an extra note, if your users are limited to specific domains, you can use the domain restriction option within BookStack itself.
Either way, to be honest I'm hesitant to expand support for additional options or providers for our social auth options.
Through our logical theme system its possible to register custom providers, so you could register a tweaked version of the default google provider if happy to hack around with PHP.
@LeafedFox commented on GitHub (Jun 23, 2022):
Hey @ssddanbrown,
It was more in reference to the Socialite side of things, Socialite::driver for example, can accept a HD param that is passed to Google. I believe it stands for 'Home Domain' or something along those lines. Essentially it instructs Google to restrict users to only those that are in the Workspace of 'example.com' - Laravels docs provide some info here: https://laravel.com/docs/9.x/socialite#optional-parameters
@ssddanbrown commented on GitHub (Jun 23, 2022):
@ItsGageH As far as I can tell Socialite does not have any built-in handling specifically for a
hdparameter.The example shown in the docs is showing how to apply any required query parameters to the redirect request. This simply then makes use of the
hdquery parameter as linked above, which alone will not securely limit google to a single workspace. End users could just modify the redirect request to alter the domain to work around any limiting/control this option might providing. It is a UI optimization only.@LeafedFox commented on GitHub (Jun 23, 2022):
@ssddanbrown Thanks for the info. I've taken a look into setting up SAML with Google, but getting stuck on login with Google returning a Error: app_not_configured_for_user - even though all the settings appear to be correct. Is this something you've encountered before? Google doesn't appear to bring any useful results.
@ssddanbrown commented on GitHub (Jun 23, 2022):
@ItsGageH I've seen a previous report for that here. As per my comment there it's worth checking against google's own documentation for that specific error message.
@ssddanbrown commented on GitHub (Jun 28, 2022):
Since there's been no follow-up required I'm going to close this. If you need any further help or have further queries just comment, and this can be re-opened if required.