feat: add OAuth2 protected resource metadata endpoint for RFC 9728 (#18643)

# Add OAuth2 Protected Resource Metadata Endpoint

This PR implements the OAuth2 Protected Resource Metadata endpoint according to RFC 9728. The endpoint is available at `/.well-known/oauth-protected-resource` and provides information about Coder as an OAuth2 protected resource.

Key changes:
- Added a new endpoint at `/.well-known/oauth-protected-resource` that returns metadata about Coder as an OAuth2 protected resource
- Created a new `OAuth2ProtectedResourceMetadata` struct in the SDK
- Added tests to verify the endpoint functionality
- Updated API documentation to include the new endpoint

The implementation currently returns basic metadata including the resource identifier and authorization server URL. The `scopes_supported` field is empty until a scope system based on RBAC permissions is implemented. The `bearer_methods_supported` field is omitted as Coder uses custom authentication methods rather than standard RFC 6750 bearer tokens.

A TODO has been added to implement RFC 6750 bearer token support in the future.
This commit is contained in:
Thomas Kosiewski
2025-07-02 18:58:41 +02:00
committed by GitHub
parent 1b73b1a12f
commit 33bbf18a4b
10 changed files with 236 additions and 2 deletions
+46
View File
@@ -65,6 +65,26 @@ const docTemplate = `{
}
}
},
"/.well-known/oauth-protected-resource": {
"get": {
"produces": [
"application/json"
],
"tags": [
"Enterprise"
],
"summary": "OAuth2 protected resource metadata.",
"operationId": "oauth2-protected-resource-metadata",
"responses": {
"200": {
"description": "OK",
"schema": {
"$ref": "#/definitions/codersdk.OAuth2ProtectedResourceMetadata"
}
}
}
}
},
"/appearance": {
"get": {
"security": [
@@ -13450,6 +13470,32 @@ const docTemplate = `{
}
}
},
"codersdk.OAuth2ProtectedResourceMetadata": {
"type": "object",
"properties": {
"authorization_servers": {
"type": "array",
"items": {
"type": "string"
}
},
"bearer_methods_supported": {
"type": "array",
"items": {
"type": "string"
}
},
"resource": {
"type": "string"
},
"scopes_supported": {
"type": "array",
"items": {
"type": "string"
}
}
}
},
"codersdk.OAuth2ProviderApp": {
"type": "object",
"properties": {