mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add azure oidc PKI auth instead of client secret (#9054)
* feat: add azure oidc PKI auth instead of client secret * add client cert and key as deployment options * Custom token refresher to handle pki auth
This commit is contained in:
+26
-3
@@ -260,9 +260,12 @@ type OAuth2GithubConfig struct {
|
||||
}
|
||||
|
||||
type OIDCConfig struct {
|
||||
AllowSignups clibase.Bool `json:"allow_signups" typescript:",notnull"`
|
||||
ClientID clibase.String `json:"client_id" typescript:",notnull"`
|
||||
ClientSecret clibase.String `json:"client_secret" typescript:",notnull"`
|
||||
AllowSignups clibase.Bool `json:"allow_signups" typescript:",notnull"`
|
||||
ClientID clibase.String `json:"client_id" typescript:",notnull"`
|
||||
ClientSecret clibase.String `json:"client_secret" typescript:",notnull"`
|
||||
// ClientKeyFile & ClientCertFile are used in place of ClientSecret for PKI auth.
|
||||
ClientKeyFile clibase.String `json:"client_key_file" typescript:",notnull"`
|
||||
ClientCertFile clibase.String `json:"client_cert_file" typescript:",notnull"`
|
||||
EmailDomain clibase.StringArray `json:"email_domain" typescript:",notnull"`
|
||||
IssuerURL clibase.String `json:"issuer_url" typescript:",notnull"`
|
||||
Scopes clibase.StringArray `json:"scopes" typescript:",notnull"`
|
||||
@@ -968,6 +971,26 @@ when required by your organization's security policy.`,
|
||||
Value: &c.OIDC.ClientSecret,
|
||||
Group: &deploymentGroupOIDC,
|
||||
},
|
||||
{
|
||||
Name: "OIDC Client Key File",
|
||||
Description: "Pem encoded RSA private key to use for oauth2 PKI/JWT authorization. " +
|
||||
"This can be used instead of oidc-client-secret if your IDP supports it.",
|
||||
Flag: "oidc-client-key-file",
|
||||
Env: "CODER_OIDC_CLIENT_KEY_FILE",
|
||||
YAML: "oidcClientKeyFile",
|
||||
Value: &c.OIDC.ClientKeyFile,
|
||||
Group: &deploymentGroupOIDC,
|
||||
},
|
||||
{
|
||||
Name: "OIDC Client Cert File",
|
||||
Description: "Pem encoded certificate file to use for oauth2 PKI/JWT authorization. " +
|
||||
"The public certificate that accompanies oidc-client-key-file. A standard x509 certificate is expected.",
|
||||
Flag: "oidc-client-cert-file",
|
||||
Env: "CODER_OIDC_CLIENT_CERT_FILE",
|
||||
YAML: "oidcClientCertFile",
|
||||
Value: &c.OIDC.ClientCertFile,
|
||||
Group: &deploymentGroupOIDC,
|
||||
},
|
||||
{
|
||||
Name: "OIDC Email Domain",
|
||||
Description: "Email domains that clients logging in with OIDC must match.",
|
||||
|
||||
Reference in New Issue
Block a user