mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add azure oidc PKI auth instead of client secret (#9054)
* feat: add azure oidc PKI auth instead of client secret * add client cert and key as deployment options * Custom token refresher to handle pki auth
This commit is contained in:
Generated
+2
@@ -256,7 +256,9 @@ curl -X GET http://coder-server:8080/api/v2/deployment/config \
|
||||
"oidc": {
|
||||
"allow_signups": true,
|
||||
"auth_url_params": {},
|
||||
"client_cert_file": "string",
|
||||
"client_id": "string",
|
||||
"client_key_file": "string",
|
||||
"client_secret": "string",
|
||||
"email_domain": ["string"],
|
||||
"email_field": "string",
|
||||
|
||||
Generated
+30
-22
@@ -2073,7 +2073,9 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
|
||||
"oidc": {
|
||||
"allow_signups": true,
|
||||
"auth_url_params": {},
|
||||
"client_cert_file": "string",
|
||||
"client_id": "string",
|
||||
"client_key_file": "string",
|
||||
"client_secret": "string",
|
||||
"email_domain": ["string"],
|
||||
"email_field": "string",
|
||||
@@ -2433,7 +2435,9 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
|
||||
"oidc": {
|
||||
"allow_signups": true,
|
||||
"auth_url_params": {},
|
||||
"client_cert_file": "string",
|
||||
"client_id": "string",
|
||||
"client_key_file": "string",
|
||||
"client_secret": "string",
|
||||
"email_domain": ["string"],
|
||||
"email_field": "string",
|
||||
@@ -3346,7 +3350,9 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
|
||||
{
|
||||
"allow_signups": true,
|
||||
"auth_url_params": {},
|
||||
"client_cert_file": "string",
|
||||
"client_id": "string",
|
||||
"client_key_file": "string",
|
||||
"client_secret": "string",
|
||||
"email_domain": ["string"],
|
||||
"email_field": "string",
|
||||
@@ -3381,28 +3387,30 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
|
||||
|
||||
### Properties
|
||||
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
| ----------------------- | -------------------------------- | -------- | ------------ | ----------- |
|
||||
| `allow_signups` | boolean | false | | |
|
||||
| `auth_url_params` | object | false | | |
|
||||
| `client_id` | string | false | | |
|
||||
| `client_secret` | string | false | | |
|
||||
| `email_domain` | array of string | false | | |
|
||||
| `email_field` | string | false | | |
|
||||
| `group_auto_create` | boolean | false | | |
|
||||
| `group_mapping` | object | false | | |
|
||||
| `group_regex_filter` | [clibase.Regexp](#clibaseregexp) | false | | |
|
||||
| `groups_field` | string | false | | |
|
||||
| `icon_url` | [clibase.URL](#clibaseurl) | false | | |
|
||||
| `ignore_email_verified` | boolean | false | | |
|
||||
| `ignore_user_info` | boolean | false | | |
|
||||
| `issuer_url` | string | false | | |
|
||||
| `scopes` | array of string | false | | |
|
||||
| `sign_in_text` | string | false | | |
|
||||
| `user_role_field` | string | false | | |
|
||||
| `user_role_mapping` | object | false | | |
|
||||
| `user_roles_default` | array of string | false | | |
|
||||
| `username_field` | string | false | | |
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
| ----------------------- | -------------------------------- | -------- | ------------ | -------------------------------------------------------------------------------- |
|
||||
| `allow_signups` | boolean | false | | |
|
||||
| `auth_url_params` | object | false | | |
|
||||
| `client_cert_file` | string | false | | |
|
||||
| `client_id` | string | false | | |
|
||||
| `client_key_file` | string | false | | Client key file & ClientCertFile are used in place of ClientSecret for PKI auth. |
|
||||
| `client_secret` | string | false | | |
|
||||
| `email_domain` | array of string | false | | |
|
||||
| `email_field` | string | false | | |
|
||||
| `group_auto_create` | boolean | false | | |
|
||||
| `group_mapping` | object | false | | |
|
||||
| `group_regex_filter` | [clibase.Regexp](#clibaseregexp) | false | | |
|
||||
| `groups_field` | string | false | | |
|
||||
| `icon_url` | [clibase.URL](#clibaseurl) | false | | |
|
||||
| `ignore_email_verified` | boolean | false | | |
|
||||
| `ignore_user_info` | boolean | false | | |
|
||||
| `issuer_url` | string | false | | |
|
||||
| `scopes` | array of string | false | | |
|
||||
| `sign_in_text` | string | false | | |
|
||||
| `user_role_field` | string | false | | |
|
||||
| `user_role_mapping` | object | false | | |
|
||||
| `user_roles_default` | array of string | false | | |
|
||||
| `username_field` | string | false | | |
|
||||
|
||||
## codersdk.Organization
|
||||
|
||||
|
||||
Generated
+20
@@ -418,6 +418,16 @@ Whether new users can sign up with OIDC.
|
||||
|
||||
OIDC auth URL parameters to pass to the upstream provider.
|
||||
|
||||
### --oidc-client-cert-file
|
||||
|
||||
| | |
|
||||
| ----------- | ----------------------------------------- |
|
||||
| Type | <code>string</code> |
|
||||
| Environment | <code>$CODER_OIDC_CLIENT_CERT_FILE</code> |
|
||||
| YAML | <code>oidc.oidcClientCertFile</code> |
|
||||
|
||||
Pem encoded certificate file to use for oauth2 PKI/JWT authorization. The public certificate that accompanies oidc-client-key-file. A standard x509 certificate is expected.
|
||||
|
||||
### --oidc-client-id
|
||||
|
||||
| | |
|
||||
@@ -428,6 +438,16 @@ OIDC auth URL parameters to pass to the upstream provider.
|
||||
|
||||
Client ID to use for Login with OIDC.
|
||||
|
||||
### --oidc-client-key-file
|
||||
|
||||
| | |
|
||||
| ----------- | ---------------------------------------- |
|
||||
| Type | <code>string</code> |
|
||||
| Environment | <code>$CODER_OIDC_CLIENT_KEY_FILE</code> |
|
||||
| YAML | <code>oidc.oidcClientKeyFile</code> |
|
||||
|
||||
Pem encoded RSA private key to use for oauth2 PKI/JWT authorization. This can be used instead of oidc-client-secret if your IDP supports it.
|
||||
|
||||
### --oidc-client-secret
|
||||
|
||||
| | |
|
||||
|
||||
Reference in New Issue
Block a user