summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorFelix Bühler <Stunkymonkey@users.noreply.github.com>2023-07-20 18:58:45 +0200
committerGitHub <noreply@github.com>2023-07-20 18:58:45 +0200
commitf7bb884c13d4ceb4cdb71fa59f212e732e1b798a (patch)
tree0f70fae4ffb8695869e29111dfcdc6c00c945d60
parentjesec-rtorrent: Add patch to prevent segfault (diff)
parentnixos/freshrss: authType option (diff)
downloadnixpkgs-f7bb884c13d4ceb4cdb71fa59f212e732e1b798a.tar.gz
Merge pull request #243850 from mattchrist/nixos/freshrss_auth_type
nixos/freshrss: authType option
-rw-r--r--nixos/modules/services/web-apps/freshrss.nix61
-rw-r--r--nixos/tests/freshrss-http-auth.nix20
-rw-r--r--pkgs/servers/web-apps/freshrss/default.nix2
3 files changed, 64 insertions, 19 deletions
diff --git a/nixos/modules/services/web-apps/freshrss.nix b/nixos/modules/services/web-apps/freshrss.nix
index 89e29f7ccb51..ffc05d0e41f8 100644
--- a/nixos/modules/services/web-apps/freshrss.nix
+++ b/nixos/modules/services/web-apps/freshrss.nix
@@ -7,7 +7,7 @@ let
poolName = "freshrss";
in
{
- meta.maintainers = with maintainers; [ etu stunkymonkey ];
+ meta.maintainers = with maintainers; [ etu stunkymonkey mattchrist ];
options.services.freshrss = {
enable = mkEnableOption (mdDoc "FreshRSS feed reader");
@@ -27,7 +27,8 @@ in
};
passwordFile = mkOption {
- type = types.path;
+ type = types.nullOr types.path;
+ default = null;
description = mdDoc "Password for the defaultUser for FreshRSS.";
example = "/run/secrets/freshrss";
};
@@ -120,7 +121,13 @@ in
user = mkOption {
type = types.str;
default = "freshrss";
- description = lib.mdDoc "User under which Freshrss runs.";
+ description = lib.mdDoc "User under which FreshRSS runs.";
+ };
+
+ authType = mkOption {
+ type = types.enum [ "form" "http_auth" "none" ];
+ default = "form";
+ description = mdDoc "Authentication type for FreshRSS.";
};
};
@@ -160,6 +167,14 @@ in
};
in
mkIf cfg.enable {
+ assertions = mkIf (cfg.authType == "form") [
+ {
+ assertion = cfg.passwordFile != null;
+ message = ''
+ `passwordFile` must be supplied when using "form" authentication!
+ '';
+ }
+ ];
# Set up a Nginx virtual host.
services.nginx = mkIf (cfg.virtualHost != null) {
enable = true;
@@ -227,7 +242,7 @@ in
settingsFlags = concatStringsSep " \\\n "
(mapAttrsToList (k: v: "${k} ${toString v}") {
"--default_user" = ''"${cfg.defaultUser}"'';
- "--auth_type" = ''"form"'';
+ "--auth_type" = ''"${cfg.authType}"'';
"--base_url" = ''"${cfg.baseUrl}"'';
"--language" = ''"${cfg.language}"'';
"--db-type" = ''"${cfg.database.type}"'';
@@ -255,20 +270,30 @@ in
FRESHRSS_DATA_PATH = cfg.dataDir;
};
- script = ''
- # do installation or reconfigure
- if test -f ${cfg.dataDir}/config.php; then
- # reconfigure with settings
- ./cli/reconfigure.php ${settingsFlags}
- ./cli/update-user.php --user ${cfg.defaultUser} --password "$(cat ${cfg.passwordFile})"
- else
- # check correct folders in data folder
- ./cli/prepare.php
- # install with settings
- ./cli/do-install.php ${settingsFlags}
- ./cli/create-user.php --user ${cfg.defaultUser} --password "$(cat ${cfg.passwordFile})"
- fi
- '';
+ script =
+ let
+ userScriptArgs = ''--user ${cfg.defaultUser} --password "$(cat ${cfg.passwordFile})"'';
+ updateUserScript = optionalString (cfg.authType == "form") ''
+ ./cli/update-user.php ${userScriptArgs}
+ '';
+ createUserScript = optionalString (cfg.authType == "form") ''
+ ./cli/create-user.php ${userScriptArgs}
+ '';
+ in
+ ''
+ # do installation or reconfigure
+ if test -f ${cfg.dataDir}/config.php; then
+ # reconfigure with settings
+ ./cli/reconfigure.php ${settingsFlags}
+ ${updateUserScript}
+ else
+ # check correct folders in data folder
+ ./cli/prepare.php
+ # install with settings
+ ./cli/do-install.php ${settingsFlags}
+ ${createUserScript}
+ fi
+ '';
};
systemd.services.freshrss-updater = {
diff --git a/nixos/tests/freshrss-http-auth.nix b/nixos/tests/freshrss-http-auth.nix
new file mode 100644
index 000000000000..d0ec3da31689
--- /dev/null
+++ b/nixos/tests/freshrss-http-auth.nix
@@ -0,0 +1,20 @@
+import ./make-test-python.nix ({ lib, pkgs, ... }: {
+ name = "freshrss";
+ meta.maintainers = with lib.maintainers; [ mattchrist ];
+
+ nodes.machine = { pkgs, ... }: {
+ services.freshrss = {
+ enable = true;
+ baseUrl = "http://localhost";
+ dataDir = "/srv/freshrss";
+ authType = "http_auth";
+ };
+ };
+
+ testScript = ''
+ machine.wait_for_unit("multi-user.target")
+ machine.wait_for_open_port(80)
+ response = machine.succeed("curl -vvv -s -H 'Host: freshrss' -H 'Remote-User: testuser' http://127.0.0.1:80/i/")
+ assert 'Account: testuser' in response, "http_auth method didn't work."
+ '';
+})
diff --git a/pkgs/servers/web-apps/freshrss/default.nix b/pkgs/servers/web-apps/freshrss/default.nix
index e43b7766a6eb..2aa727ca2d14 100644
--- a/pkgs/servers/web-apps/freshrss/default.nix
+++ b/pkgs/servers/web-apps/freshrss/default.nix
@@ -18,7 +18,7 @@ stdenvNoCC.mkDerivation rec {
};
passthru.tests = {
- inherit (nixosTests) freshrss-sqlite freshrss-pgsql;
+ inherit (nixosTests) freshrss-sqlite freshrss-pgsql freshrss-http-auth;
};
buildInputs = [ php ];