[PR #6885] [client] add flag to force device code auth #29998

Open
opened 2026-08-05 08:09:39 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/6885
Author: @andreasgerner
Created: 7/24/2026
Status: 🔄 Open

Base: mainHead: feat/device-code-auth


📝 Commits (3)

  • 64804ae [client] add flag to force device code auth
  • 4ae04a8 Merge branch 'main' into feat/device-code-auth
  • 6ee1dbb [client] reuse cached OAuth flow only when auth mode matches flag

📊 Changes

7 files changed (+62 additions, -10 deletions)

View changed files

📝 client/cmd/login.go (+6 -1)
📝 client/cmd/up.go (+9 -0)
client/internal/auth/oauth_test.go (+20 -0)
📝 client/proto/daemon.pb.go (+18 -6)
📝 client/proto/daemon.proto (+4 -0)
📝 client/proto/daemon_grpc.pb.go (+1 -1)
📝 client/server/server.go (+4 -2)

📄 Description

Describe your changes

Add a flag to cli up & login commands to force client to use device code flow.

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/883


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Summary by CodeRabbit

  • New Features
    • Added support for device-based authentication during login.
    • Introduced a --use-device-auth flag to drive the same behavior when starting the service.
    • Authentication and SSO OAuth flows now respect the selected device-auth preference, including proper reuse of cached SSO flows.
  • Tests
    • Added unit tests verifying device-flow selection for forced device flow and non-forced desktop behavior.

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/6885 **Author:** [@andreasgerner](https://github.com/andreasgerner) **Created:** 7/24/2026 **Status:** 🔄 Open **Base:** `main` ← **Head:** `feat/device-code-auth` --- ### 📝 Commits (3) - [`64804ae`](https://github.com/netbirdio/netbird/commit/64804ae864ad81ce91d96b866b0f2ed1ebfdd5a9) [client] add flag to force device code auth - [`4ae04a8`](https://github.com/netbirdio/netbird/commit/4ae04a821fedf3b6b1e781f9ad52a4d511615b9a) Merge branch 'main' into feat/device-code-auth - [`6ee1dbb`](https://github.com/netbirdio/netbird/commit/6ee1dbb26906778f2ded339dd849d41df9d5cac0) [client] reuse cached OAuth flow only when auth mode matches flag ### 📊 Changes **7 files changed** (+62 additions, -10 deletions) <details> <summary>View changed files</summary> 📝 `client/cmd/login.go` (+6 -1) 📝 `client/cmd/up.go` (+9 -0) ➕ `client/internal/auth/oauth_test.go` (+20 -0) 📝 `client/proto/daemon.pb.go` (+18 -6) 📝 `client/proto/daemon.proto` (+4 -0) 📝 `client/proto/daemon_grpc.pb.go` (+1 -1) 📝 `client/server/server.go` (+4 -2) </details> ### 📄 Description ## Describe your changes Add a flag to cli up & login commands to force client to use device code flow. ### Checklist - [ ] Is it a bug fix - [ ] Is a typo/documentation fix - [x] Is a feature enhancement - [ ] It is a refactor - [x] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [x] I added/updated documentation for this change - [ ] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/883 <!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/netbirdio/codesmith/netbird/pr/6885"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787490647&installation_model_id=427504&pr_number=6885&repository=netbirdio%2Fnetbird&return_to=https%3A%2F%2Fgithub.com%2Fnetbirdio%2Fnetbird%2Fpull%2F6885&signature=bd858d847cee7e4148f52be33db77d43a88ae8293ef565f6f6cfcf08201a5adb"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img alt="Autofix with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a> <sup>Need help on this PR? Tag <code>@codesmith-bot</code> with what you need. Autofix is disabled.</sup> <!-- codesmith:autofix:disabled --> <!-- /codesmith:footer --> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for device-based authentication during login. * Introduced a `--use-device-auth` flag to drive the same behavior when starting the service. * Authentication and SSO OAuth flows now respect the selected device-auth preference, including proper reuse of cached SSO flows. * **Tests** * Added unit tests verifying device-flow selection for forced device flow and non-forced desktop behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 08:09:39 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#29998