diff --git a/services/authelia.sh b/services/authelia.sh index 3d0a63b..72cfea7 100644 --- a/services/authelia.sh +++ b/services/authelia.sh @@ -242,10 +242,10 @@ install_authelia() { echo " or type one on a different box — gates it with a login, same as any" echo " other service already protected this way)" echo " 11) Un-protect a site (undoes option 10 for one site)" - echo " 12) Leave as-is" + echo " 0) Leave as-is / exit" echo "" local EXISTING_CHOICE="" - prompt_text " Choice [1/2/3/4/5/6/7/8/9/10/11/12]:" "12" EXISTING_CHOICE + prompt_text " Choice [1-11, 0 to exit]:" "0" EXISTING_CHOICE case "$EXISTING_CHOICE" in 1) add_authelia_domain @@ -290,7 +290,7 @@ install_authelia() { _authelia_unprotect_site return 0 ;; - *) + 0|*) echo " Keeping existing Authelia. (Edit config/users.yml then: cd $AUTHELIA_DIR && docker compose restart authelia)" return 0 ;; @@ -574,7 +574,8 @@ added to \`$DOCKER_DIR/caddy/Caddyfile\` automatically. Re-run this installer (\`sudo ./setup.sh authelia\` or \`sudo bash authelia.sh\`) and choose **"Add another protected domain to this instance"** when it detects the existing install. That domain gets its own \`session.cookies\` entry and its -own \`auth.\` portal — a separate login/session from ${AUTHELIA_DOMAIN}, +own login portal (you'll be asked what subdomain to use — "auth" is just the +suggested default) — a separate login/session from ${AUTHELIA_DOMAIN}, so no accidental cross-domain SSO — but it's still one shared Authelia + Redis container and one shared user database, not a second full stack. Cheaper than standing up an entirely separate instance, and the right way to protect @@ -676,9 +677,9 @@ add_authelia_domain() { echo "" echo " Add another apex domain to this Authelia instance." - echo " It gets its own session-cookie scope and its own auth. portal —" - echo " a separate login/session from your other domain(s) — but shares this" - echo " same Authelia + Redis container, not a second full stack." + echo " It gets its own session-cookie scope and its own login portal (you'll pick" + echo " the subdomain next — a separate login/session from your other domain(s))" + echo " but shares this same Authelia + Redis container, not a second full stack." echo "" local NEW_DOMAIN="" prompt_text " New domain (e.g., example.com):" "" NEW_DOMAIN @@ -824,28 +825,36 @@ remove_authelia_domain() { return 1 fi + local -a apex_domains + mapfile -t apex_domains < <(grep -oE '^ - domain: "\*\.[^"]+"' "$CONFIG_FILE" | sed -E 's/^ - domain: "\*\.(.+)"$/\1/') + echo "" + if [ "${#apex_domains[@]}" -eq 0 ]; then + log_info "No apex domains found on this instance." + return 0 + fi echo " Domains currently on this Authelia instance:" - grep -oE '^ - domain: "\*\.[^"]+"' "$CONFIG_FILE" | sed -E 's/^ - domain: "\*\.(.+)"$/ - \1/' + local i + for i in "${!apex_domains[@]}"; do + echo " $((i + 1))) ${apex_domains[$i]}" + done + echo " 0) Cancel" echo "" echo " Note: this removes a whole apex domain entry added via 'Add another" echo " protected domain' — if you meant to protect a SUBDOMAIN of an apex" echo " already listed above, you don't need this at all: it's already covered" echo " by that apex's wildcard rule and session-cookie scope. Just point that" - echo " subdomain's Caddy block at this instance's existing auth. portal" - echo " instead of adding it here as its own entry." + echo " subdomain's Caddy block at this instance's existing login portal for that" + echo " apex instead of adding it here as its own entry — option 10 (Protect an" + echo " existing site) will find and use the right one automatically." echo "" - local RM_DOMAIN="" - prompt_text " Domain to remove (as shown above, e.g. example.com):" "" RM_DOMAIN - if [ -z "$RM_DOMAIN" ]; then - log_warning "No domain entered — nothing to do." - return 0 - fi - - if ! grep -qF "\"*.${RM_DOMAIN}\"" "$CONFIG_FILE" 2>/dev/null; then - log_warning "$RM_DOMAIN isn't configured on this instance — nothing to do." + local RM_CHOICE="" + prompt_text " Number to remove, or 0 [0]:" "0" RM_CHOICE + if ! [[ "$RM_CHOICE" =~ ^[0-9]+$ ]] || [ "$RM_CHOICE" -lt 1 ] || [ "$RM_CHOICE" -gt "${#apex_domains[@]}" ]; then + log_info "Cancelled — nothing changed." return 0 fi + local RM_DOMAIN="${apex_domains[$((RM_CHOICE - 1))]}" # Read the portal's own domain back from this apex's session.cookies # entry — it's whatever subdomain was chosen when this domain was added @@ -990,11 +999,12 @@ _authelia_protect_site() { fi echo " Or type a domain directly — including one on a DIFFERENT box's Caddy" echo " entirely (this box only needs to run Authelia itself for that to work)." + echo " 0 to cancel." echo "" local choice="" - prompt_text " Number or domain:" "" choice - if [ -z "$choice" ]; then - log_warning "Nothing entered — nothing to do." + prompt_text " Number, domain, or 0 [0]:" "0" choice + if [ -z "$choice" ] || [ "$choice" = "0" ]; then + log_info "Cancelled — nothing changed." return 0 fi @@ -1125,10 +1135,11 @@ _authelia_unprotect_site() { echo " Or type a domain directly — including one on a different box's Caddy, to" echo " clean up its access-scoping rules here even though the gate itself lives" echo " elsewhere and needs removing there by hand." + echo " 0 to cancel." echo "" local choice="" - prompt_text " Number or domain (blank to cancel):" "" choice - if [ -z "$choice" ]; then + prompt_text " Number, domain, or 0 [0]:" "0" choice + if [ -z "$choice" ] || [ "$choice" = "0" ]; then log_info "Cancelled — nothing changed." return 0 fi @@ -1516,11 +1527,11 @@ _authelia_scope_access() { echo "" echo " Who should be able to reach $domain via Authelia?" - echo " 1) Any Authelia user (default — same access as everything else)" - echo " 2) Specific users only" + echo " 1) Specific users only" + echo " 0) Any Authelia user (default — same access as everything else)" local scope_choice="" - prompt_text " Choice [1/2]:" "1" scope_choice - [ "$scope_choice" = "2" ] || return 0 + prompt_text " Choice [1, or 0 for any user]:" "0" scope_choice + [ "$scope_choice" = "1" ] || return 0 local -a existing_users mapfile -t existing_users < <(_authelia_list_usernames "$users_file") @@ -1813,10 +1824,10 @@ edit_authelia_user() { done echo "" echo " Select one or more by number (space-separated, e.g. \"2 4\")," - echo " blank to cancel." + echo " or 0 to cancel." local SEL="" - prompt_text " User number(s):" "" SEL - if [ -z "$SEL" ]; then + prompt_text " User number(s) [0]:" "0" SEL + if [ -z "$SEL" ] || [ "$SEL" = "0" ]; then log_info "Cancelled." return 0 fi @@ -1881,10 +1892,10 @@ _authelia_manage_one_user() { fi echo " 6) Promote to (or remove from) a specific service's access group" echo " 7) Delete this user" - echo " 8) Done with this user" + echo " 0) Done with this user" echo "" local ACTION="" - prompt_text " Choice [1-8]:" "8" ACTION + prompt_text " Choice [1-7, 0 when done]:" "0" ACTION case "$ACTION" in 1) @@ -1972,9 +1983,9 @@ _authelia_manage_one_user() { done echo "" echo " Pick by number (space-separated) to toggle — a member gets removed," - echo " a non-member gets added. Blank to leave unchanged." + echo " a non-member gets added. 0 (or blank) to leave unchanged." local TOGGLE_SEL="" - prompt_text " Numbers:" "" TOGGLE_SEL + prompt_text " Numbers [0]:" "0" TOGGLE_SEL local -a TOGGLE_TOKENS read -ra TOGGLE_TOKENS <<< "$TOGGLE_SEL" local tk tidx tgrp t_start t_end t_range is_member @@ -2015,8 +2026,8 @@ _authelia_manage_one_user() { log_info "Left as-is." fi ;; - *) - ACTION="8" + 0|*) + ACTION="0" ;; esac @@ -2357,9 +2368,10 @@ _authelia_add_oidc_client() { echo " 3) Immich (needs multiple redirect URIs — web login, account-linking," echo " and the mobile app's custom-scheme callback — all registered here)" echo " 4) Other / custom app" + echo " 0) Cancel" echo "" local APP_CHOICE="" - prompt_text " Choice [1/2/3/4]:" "4" APP_CHOICE + prompt_text " Choice [1-4, 0 to cancel]:" "0" APP_CHOICE local APP_NAME="" CLIENT_ID="" local -a REDIRECT_PATHS=() EXTRA_REDIRECT_URIS=() @@ -2371,7 +2383,7 @@ _authelia_add_oidc_client() { REDIRECT_PATHS=("/auth/login" "/user-settings") EXTRA_REDIRECT_URIS=("app.immich:///oauth-callback") ;; - *) + 4) prompt_text " App name (for your reference):" "" APP_NAME [ -z "$APP_NAME" ] && { log_warning "No app name entered — nothing to do."; return 0; } CLIENT_ID="$(echo "$APP_NAME" | tr '[:upper:]' '[:lower:]' | tr -cs 'a-z0-9' '-' | sed 's/^-*//;s/-*$//')" @@ -2382,6 +2394,10 @@ _authelia_add_oidc_client() { prompt_text " Redirect URI path (starting with /):" "" _redirect_path [ -n "$_redirect_path" ] && REDIRECT_PATHS=("$_redirect_path") ;; + 0|*) + log_info "Cancelled — nothing changed." + return 0 + ;; esac if [ -z "$CLIENT_ID" ] || { [ "${#REDIRECT_PATHS[@]}" -eq 0 ] && [ "${#EXTRA_REDIRECT_URIS[@]}" -eq 0 ]; }; then log_warning "Missing client ID or redirect path — nothing to do." @@ -2511,10 +2527,11 @@ _authelia_remove_oidc_client_menu() { for i in "${!client_ids[@]}"; do echo " $((i + 1))) ${client_ids[$i]} (${client_names[$i]:-unnamed})" done + echo " 0) Cancel" echo "" local choice="" - prompt_text " Number to remove (blank to cancel):" "" choice - if [ -z "$choice" ] || ! [[ "$choice" =~ ^[0-9]+$ ]] || [ "$choice" -lt 1 ] || [ "$choice" -gt "${#client_ids[@]}" ]; then + prompt_text " Number to remove, or 0 [0]:" "0" choice + if ! [[ "$choice" =~ ^[0-9]+$ ]] || [ "$choice" -lt 1 ] || [ "$choice" -gt "${#client_ids[@]}" ]; then log_info "Cancelled — nothing changed." return 0 fi