Merge pull request #577 from christianlouis/copilot/create-user-auth-workflow

fix(templates): remove orphan `</div>` in google_drive.html breaking HTML accessibility lint
This commit is contained in:
Christian Krakau-Louis
2026-03-10 00:00:39 +01:00
committed by GitHub
16 changed files with 874 additions and 188 deletions
+27 -13
View File
@@ -15,23 +15,37 @@ For a complete list of configuration options, see the [Configuration Guide](Conf
## Setup Methods
You can set up Dropbox integration in two ways:
DocuElevate supports two distinct Dropbox OAuth flows:
1. **Using the Built-in Setup Wizard (Recommended)**: An interactive setup experience available at `/dropbox-setup` in the web interface
2. **Manual Setup**: Following the step-by-step instructions in this document
1. **Per-User Integration Wizard (Recommended for end users)**: Triggered from the Integrations dashboard (`/integrations`) by clicking **Authorize** on a Dropbox destination or Dropbox-backed Watch Folder. Credentials are saved securely to your personal integration record — global settings are never exposed.
2. **System-Level Setup Wizard**: Available at `/dropbox-setup` for administrators configuring the global system-wide Dropbox connection. Generates environment variables for all worker nodes.
3. **Manual Setup**: Following the step-by-step instructions in this document.
## Using the Setup Wizard
## Per-User OAuth Flow (Integrations Dashboard)
The easiest way to set up Dropbox integration is to use the built-in setup wizard:
End users authorize their own Dropbox integration from the **Integrations** dashboard:
1. Navigate to the `/dropbox-setup` page in your DocuElevate instance
2. Follow the on-screen instructions to create a Dropbox app
3. Enter your App Key and App Secret in the wizard
4. Optionally specify a custom folder path for uploads
5. Click "Start Authentication Flow" to begin the authorization process
6. Complete the Dropbox authentication process
7. The system will automatically exchange the authorization code for a refresh token
8. Copy the generated environment variables for your worker nodes
1. Navigate to `/integrations` and click **+ Add Destination** (or **+ Add Source** for Watch Folder).
2. Create a Dropbox destination integration (or a Watch Folder with `source_type = dropbox`).
3. Click the **Authorize** button next to the integration — it links directly to the OAuth wizard pre-loaded with your integration's configuration.
4. Enter your Dropbox App Key and App Secret in the wizard (or use the global admin credentials if pre-configured).
5. Click **Start Authentication Flow**, authorize access in Dropbox, and the refresh token is automatically saved to your personal integration record.
6. The page redirects back to `/integrations` on success. Re-authorization is available at any time via the **Re-Authorize** button.
> **Note:** Your credentials are stored encrypted per-integration and are never mixed with other users' data. Each user can have multiple Dropbox integrations with independent tokens.
## Using the System-Level Setup Wizard (Admin)
The easiest way to configure the global Dropbox integration is to use the built-in setup wizard:
1. Navigate to the `/dropbox-setup` page in your DocuElevate instance.
2. Follow the on-screen instructions to create a Dropbox app.
3. Enter your App Key and App Secret in the wizard.
4. Optionally specify a custom folder path for uploads.
5. Click **Start Authentication Flow** to begin the authorization process.
6. Complete the Dropbox authentication process.
7. The system will automatically exchange the authorization code for a refresh token.
8. Copy the generated environment variables for your worker nodes.
The wizard handles all the token exchange steps and provides you with the exact configuration needed for your environment.
+16 -2
View File
@@ -16,14 +16,28 @@ This guide explains how to set up the Google Drive integration for DocuElevate.
For a complete list of configuration options, see the [Configuration Guide](ConfigurationGuide.md).
## Authentication Methods
## Authentication Methods and Setup Flows
DocuElevate supports two authentication methods for Google Drive:
1. **OAuth Authentication (Recommended)** - User-based authentication that provides better security and control. Recommended for most deployments.
2. **Service Account Authentication** - Server-to-server authentication that doesn't require user interaction. Useful for specific enterprise deployments.
## Method 1: OAuth Authentication Setup (Recommended)
### Per-User OAuth Flow (Integrations Dashboard)
End users can authorize their own Google Drive integration directly from the **Integrations** dashboard — no admin involvement required:
1. Navigate to `/integrations` and click **+ Add Destination** (or **+ Add Source** for Watch Folder).
2. Create a Google Drive destination integration (or a Watch Folder with `source_type = google_drive`).
3. Click the **Authorize** button — it opens the OAuth wizard pre-loaded with your integration's configuration.
4. Enter your Google OAuth Client ID and Client Secret in the wizard.
5. Click **Start Authentication Flow** and authorize access in Google.
6. Credentials are saved automatically to your personal integration record; the page redirects back to `/integrations`.
7. Re-authorization is available at any time via the **Re-Authorize** button.
> **Note:** Credentials are stored encrypted per-integration. Each user can hold multiple Google Drive integrations with independent tokens targeting different folders or accounts.
## Method 1: OAuth Authentication Setup (System-Level)
The OAuth method is preferred as it:
- Provides better security with token expiration and refresh
+26 -12
View File
@@ -16,22 +16,36 @@ For a complete list of configuration options, see the [Configuration Guide](Conf
## Setup Methods
You can set up OneDrive integration in two ways:
DocuElevate supports two distinct OneDrive OAuth flows:
1. **Using the Auth Wizard (Recommended)**: An interactive setup experience available at `/onedrive-setup` in the web interface
2. **Manual Setup**: Following the step-by-step instructions in this document
1. **Per-User Integration Wizard (Recommended for end users)**: Triggered from the Integrations dashboard (`/integrations`) by clicking **Authorize** on a OneDrive destination or OneDrive-backed Watch Folder. Credentials are saved securely to your personal integration record.
2. **System-Level Setup Wizard**: Available at `/onedrive-setup` for administrators configuring the global system-wide OneDrive connection.
3. **Manual Setup**: Following the step-by-step instructions in this document.
## Using the Auth Wizard
## Per-User OAuth Flow (Integrations Dashboard)
The easiest way to set up OneDrive integration is to use the built-in auth wizard:
End users authorize their own OneDrive integration from the **Integrations** dashboard:
1. Register an application in Azure AD (see steps below)
2. Navigate to the OneDrive Setup page at `/onedrive-setup`
3. Enter your Client ID and other required information
4. Click "Start Authentication Flow"
5. Complete the Microsoft authentication process
6. The system will automatically exchange the authorization code for a refresh token
7. Copy the generated environment variables for your worker nodes
1. Navigate to `/integrations` and click **+ Add Destination** (or **+ Add Source** for Watch Folder).
2. Create a OneDrive destination integration (or a Watch Folder with `source_type = onedrive`).
3. Click the **Authorize** button next to the integration — it links directly to the OAuth wizard pre-loaded with your integration's configuration.
4. Enter your Azure AD Client ID and Client Secret in the wizard.
5. Click **Start Authentication Flow**, authorize access via Microsoft, and the refresh token is automatically saved to your personal integration record.
6. The page redirects back to `/integrations` on success. Re-authorization is available at any time via the **Re-Authorize** button.
> **Note:** Your credentials are stored encrypted per-integration and are never mixed with other users' data. Each user can have multiple OneDrive integrations with independent tokens.
## Using the System-Level Auth Wizard (Admin)
The easiest way to configure the global OneDrive integration is to use the built-in auth wizard:
1. Register an application in Azure AD (see steps below).
2. Navigate to the OneDrive Setup page at `/onedrive-setup`.
3. Enter your Client ID and other required information.
4. Click **Start Authentication Flow**.
5. Complete the Microsoft authentication process.
6. The system will automatically exchange the authorization code for a refresh token.
7. Copy the generated environment variables for your worker nodes.
The auth wizard handles all the token exchange steps and provides you with the exact configuration needed for your environment.