1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
{
"$schema": "http://json-schema.org/draft-04/schema#",
"description": "",
"type": "object",
"properties": {
"salt": {
"type": "string",
"pattern": "^[0-9a-fA-F]{16}$",
"description": "16-character hex salt applied to local password hashes."
},
"auth_mode": {
"type": "string",
"pattern": "^(oauth|local|both)$"
},
"oauth_provider": {
"type": "string",
"pattern": "^(google|github)?$"
},
"oauth_client_id": {
"type": "string",
"minLength": 0
},
"oauth_client_secret": {
"type": "string",
"minLength": 0
},
"oauth_redirect_uri": {
"type": "string",
"minLength": 0
},
"oauth_username_from": {
"type": "string",
"pattern": "^(sub|email|preffered_username|login|name)$"
},
"oauth_allowed_emails": {
"type": "array",
"description": "OAuth sign-in allowlist. Empty allows all. Entries support fnmatch globs (*, ?) on the normalized e-mail.",
"items": {
"type": "string",
"minLength": 1
}
},
"oauth_permissions": {
"type": "object",
"description": "Map of permission keys to principal emails (or local usernames). Key * grants all permissions.",
"properties": {
"*": {
"type": "array",
"items": { "type": "string" }
},
"pgw.addprojects": {
"type": "array",
"items": { "type": "string" }
},
"pgw.settings": {
"type": "array",
"items": { "type": "string" }
}
},
"additionalProperties": {
"type": "array",
"items": { "type": "string" },
"description": "Scoped keys: pgw.boards.{scope}, pgw.tasks.{scope}, pgw.comments.{scope}, pgw.hooks.{scope}, pgw.mr.create.{scope}, pgw.mr.merge.{scope} (fnmatch on project path)"
}
},
"local_users": {
"type": "array",
"uniqueItems": true,
"minItems": 1,
"items": {
"required": [
"user"
],
"oneOf": [
{ "required": ["pass_hash"] },
{ "required": ["pass"] }
],
"properties": {
"user": {
"type": "string",
"minLength": 2
},
"pass": {
"type": "string",
"minLength": 8,
"description": "Plaintext password; hashed to pass_hash on first server start, then removed."
},
"pass_hash": {
"type": "string",
"minLength": 1,
"description": "scrypt password hash (written by the server)."
},
"email": {
"type": "string",
"format": "email",
"description": "Optional e-mail for Gravatar and permission grants by principal e-mail."
}
}
}
}
},
"required": [
"auth_mode",
"salt"
]
}