<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[New update overwrites default auth?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I saw this update description yesterday:</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> said in <a href="/post/74366">Gitea - Package Updates</a>:</p>
<blockquote>
<p dir="auto">[1.30.0]</p>
<ul>
<li>Implement OIDC auth</li>
</ul>
</blockquote>
<p dir="auto">I had previously manually configured oidc in my Gitea and it looks like this update overwrote the old LDAP based login. This means I have now two oidc logins, but only my manually created one works.</p>
]]></description><link>https://forum.cloudron.io/topic/10113/new-update-overwrites-default-auth</link><generator>RSS for Node</generator><lastBuildDate>Thu, 17 Sep 2026 03:15:30 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/10113.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 29 Sep 2023 06:33:10 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to New update overwrites default auth? on Fri, 29 Sep 2023 14:23:06 GMT]]></title><description><![CDATA[<p dir="auto">In the browser, it says : "2FA token is invalid".<br />
In the app logs, I can see no error</p>
]]></description><link>https://forum.cloudron.io/post/74442</link><guid isPermaLink="true">https://forum.cloudron.io/post/74442</guid><dc:creator><![CDATA[Aeton]]></dc:creator><pubDate>Fri, 29 Sep 2023 14:23:06 GMT</pubDate></item><item><title><![CDATA[Reply to New update overwrites default auth? on Fri, 29 Sep 2023 12:31:20 GMT]]></title><description><![CDATA[<p dir="auto">If the app is configured to use the Cloudron usermanagement, which it is, if you see the OpenID login button, then the username/password login form does not work anymore. That is to be expected and one of the upsides of OpenID, that the credentials are not passed through the app code at all.</p>
<p dir="auto">For the OpenID login issue, do you see any error in the browser or the app logs?</p>
]]></description><link>https://forum.cloudron.io/post/74431</link><guid isPermaLink="true">https://forum.cloudron.io/post/74431</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Fri, 29 Sep 2023 12:31:20 GMT</pubDate></item><item><title><![CDATA[Reply to New update overwrites default auth? on Fri, 29 Sep 2023 12:23:26 GMT]]></title><description><![CDATA[<p dir="auto">Hello,<br />
Since this update, I can no longer login in my user account (with password and 2fa Yubikey).<br />
I have also tried the new icon "sign in with cloudron" but it does not event work.</p>
<p dir="auto">Hopefully, I can login with the root logins. So my question is : What can I do to make my login with user account works again ? Do I need to disable the OAuth2 configured in the authentification sources/configurations of gitea ?</p>
<p dir="auto">Thank you</p>
]]></description><link>https://forum.cloudron.io/post/74430</link><guid isPermaLink="true">https://forum.cloudron.io/post/74430</guid><dc:creator><![CDATA[Aeton]]></dc:creator><pubDate>Fri, 29 Sep 2023 12:23:26 GMT</pubDate></item><item><title><![CDATA[Reply to New update overwrites default auth? on Fri, 29 Sep 2023 10:38:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> it definitely is cumbersome when additionally using 2fa in Gitea.</p>
]]></description><link>https://forum.cloudron.io/post/74418</link><guid isPermaLink="true">https://forum.cloudron.io/post/74418</guid><dc:creator><![CDATA[fbartels]]></dc:creator><pubDate>Fri, 29 Sep 2023 10:38:06 GMT</pubDate></item><item><title><![CDATA[Reply to New update overwrites default auth? on Fri, 29 Sep 2023 10:35:58 GMT]]></title><description><![CDATA[<p dir="auto">Yeah I initially also preferred LDAP for no real reason but just being used to that flow, now since we moved a bunch of apps over to OpenID, my habit changed and username/password login feels cumbersome <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=cda77ebfe05" class="not-responsive emoji emoji-android emoji--smile" style="height:23px;width:auto;vertical-align:middle" title=":D" alt="😄" /></p>
]]></description><link>https://forum.cloudron.io/post/74417</link><guid isPermaLink="true">https://forum.cloudron.io/post/74417</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Fri, 29 Sep 2023 10:35:58 GMT</pubDate></item><item><title><![CDATA[Reply to New update overwrites default auth? on Fri, 29 Sep 2023 10:29:51 GMT]]></title><description><![CDATA[<p dir="auto">The manual one was freed up, after I manually removed it from "Manage Linked Accounts" in my users security settings. Afterwards I could delete it.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> said in <a href="/post/74413">New update overwrites default auth?</a>:</p>
<blockquote>
<p dir="auto">just because of habit?</p>
</blockquote>
<p dir="auto">Yes exactly this. You could argue however that the the oidc login is more secure.</p>
]]></description><link>https://forum.cloudron.io/post/74416</link><guid isPermaLink="true">https://forum.cloudron.io/post/74416</guid><dc:creator><![CDATA[fbartels]]></dc:creator><pubDate>Fri, 29 Sep 2023 10:29:51 GMT</pubDate></item><item><title><![CDATA[Reply to New update overwrites default auth? on Fri, 29 Sep 2023 10:06:56 GMT]]></title><description><![CDATA[<p dir="auto">Is the manual auth source freed up after the first Cloudron OpenID login (assuming the usermapping worked)?</p>
<p dir="auto">For the login form, is there a practical use-case for this instead of OpenID or just because of habit?</p>
]]></description><link>https://forum.cloudron.io/post/74413</link><guid isPermaLink="true">https://forum.cloudron.io/post/74413</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Fri, 29 Sep 2023 10:06:56 GMT</pubDate></item><item><title><![CDATA[Reply to New update overwrites default auth? on Fri, 29 Sep 2023 10:04:25 GMT]]></title><description><![CDATA[<p dir="auto">My Gitea is so old, I don't even have the default root user <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f605.png?v=cda77ebfe05" class="not-responsive emoji emoji-android emoji--sweat_smile" style="height:23px;width:auto;vertical-align:middle" title="😅" alt="😅" />. But I saw that you can list and change password with <code>sudo -H -u git /home/git/gitea/gitea admin user list -c /run/gitea/app.ini</code> in the worst case.</p>
<p dir="auto">My main user is an admin in gitea, so I tried to delete my manually configured out, but Gitea replies with: "The authentication source is still in use. Convert or delete any users using this authentication source first.", so I opted to disable it instead. In addition I deleted the client configuration from the Cloudron user directory settings.</p>
<p dir="auto">After a restart of the Gitea app the new Cloudron login works.</p>
<p dir="auto">However: I think grumpy old me would still have preferred to keep ldap auth as an option, because now I am forced to login via oidc, whereas before I still had the option to use the username and password fields that gitea displays by default. (I can still use these, but then I have to manually set a password for the user I just used oidc to log in to).</p>
]]></description><link>https://forum.cloudron.io/post/74412</link><guid isPermaLink="true">https://forum.cloudron.io/post/74412</guid><dc:creator><![CDATA[fbartels]]></dc:creator><pubDate>Fri, 29 Sep 2023 10:04:25 GMT</pubDate></item><item><title><![CDATA[Reply to New update overwrites default auth? on Fri, 29 Sep 2023 09:38:39 GMT]]></title><description><![CDATA[<p dir="auto">Presumably you've already tried that, but can you login with the root/admin account and remove the custom OpenID authentication source?</p>
]]></description><link>https://forum.cloudron.io/post/74411</link><guid isPermaLink="true">https://forum.cloudron.io/post/74411</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Fri, 29 Sep 2023 09:38:39 GMT</pubDate></item></channel></rss>