New
- agents: add pre-review quality pass (#97) (35a42b0974fb)
- ui: improve provider endpoint and profile controls (#95) (e3858ed46094)
- test: validate the OIDC sign-out lifecycle (#89) (c1e8d21b2531)
- setup: brand applications by WebGUI FQDN (#86) (f22d78b6797d)
- ui: add form revert and sign-in guidance (#85) (c85e0e16e19f)
- ui: assign local groups while adding identities (#83) (eeaf7d03f885)
Fixed
- contribution: avoid coordination cross-references (#94) (896c59298fb5)
- contribution: maintain agent review lifecycle (#91) (399d4d79aad4)
- contribution: stabilize merge-order replacements (#88) (aab4959a6262)
- oidc: make proxied sign-in outcomes actionable (#80) (470079cbf580)
Documentation
- contribution: document maintained detail comments (#77) (697f8df9f17d)
Verify and install
pkg checks nothing about a file handed to it directly. Establish its
GitHub/Sigstore provenance before the package reaches the firewall.
On an administrator workstation:
curl --fail --location --output /tmp/os-openid-connect-1.0.0.beta3.pkg \
https://github.com/jpawlowski/opnsense-openid-connect/releases/download/v1.0.0-beta3/os-openid-connect-1.0.0.beta3.pkg
gh attestation verify /tmp/os-openid-connect-1.0.0.beta3.pkg \
-R jpawlowski/opnsense-openid-connect \
--signer-workflow jpawlowski/opnsense-openid-connect/.github/workflows/build.yml \
--deny-self-hosted-runners
Copy that verified package to /tmp on the firewall. Confirm that the
transfer preserved its exact bytes, then install it:
sha256 -c 6c629dfb1d26e5f6a4acb5eaeefd1865c6a6ca7bb4afd0b261d4f2f476db44fc /tmp/os-openid-connect-1.0.0.beta3.pkg
pkg add /tmp/os-openid-connect-1.0.0.beta3.pkg
No restart, no service affected. Signing in locally with a username and
password is untouched; the way back is always
pkg delete os-openid-connect.
11 commit(s) since v1.0.0-beta2.
Built from 896c59298fb5d642404cc72957ceda8908600d19.