mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: implement SCIM handler for SCIM 2.0 compliance (#25572)
Rewrites the SCIM 2.0 user provisioning handler to be RFC 7644 compliant. Verified against an external IdP Okta. Behavior is OPT IN
This commit is contained in:
@@ -638,6 +638,7 @@ type DeploymentValues struct {
|
||||
AgentFallbackTroubleshootingURL serpent.URL `json:"agent_fallback_troubleshooting_url,omitempty" typescript:",notnull"`
|
||||
BrowserOnly serpent.Bool `json:"browser_only,omitempty" typescript:",notnull"`
|
||||
SCIMAPIKey serpent.String `json:"scim_api_key,omitempty" typescript:",notnull"`
|
||||
UseLegacySCIM serpent.Bool `json:"scim_use_legacy,omitempty" typescript:",notnull"`
|
||||
ExternalTokenEncryptionKeys serpent.StringArray `json:"external_token_encryption_keys,omitempty" typescript:",notnull"`
|
||||
Provisioner ProvisionerConfig `json:"provisioner,omitempty" typescript:",notnull"`
|
||||
RateLimit RateLimitConfig `json:"rate_limit,omitempty" typescript:",notnull"`
|
||||
@@ -3447,6 +3448,18 @@ func (c *DeploymentValues) Options() serpent.OptionSet {
|
||||
Annotations: serpent.Annotations{}.Mark(annotationEnterpriseKey, "true").Mark(annotationSecretKey, "true"),
|
||||
Value: &c.SCIMAPIKey,
|
||||
},
|
||||
{
|
||||
Name: "SCIM Use Legacy",
|
||||
// The legacy SCIM is a weird mix of SCIM 1.0 and SCIM 2.0
|
||||
Description: "Use the legacy SCIM implementation instead of the SCIM 2.0 handler. This is provided for backward compatibility for existing users.",
|
||||
Flag: "scim-use-legacy",
|
||||
Env: "CODER_SCIM_USE_LEGACY",
|
||||
Hidden: true,
|
||||
// TODO: When SCIM 2.0 has been tested more, flip this to false to default to the new scim
|
||||
Default: "true",
|
||||
Annotations: serpent.Annotations{}.Mark(annotationEnterpriseKey, "true"),
|
||||
Value: &c.UseLegacySCIM,
|
||||
},
|
||||
{
|
||||
Name: "External Token Encryption Keys",
|
||||
Description: "Encrypt OIDC and Git authentication tokens with AES-256-GCM in the database. The value must be a comma-separated list of base64-encoded keys. Each key, when base64-decoded, must be exactly 32 bytes in length. The first key will be used to encrypt new values. Subsequent keys will be used as a fallback when decrypting. During normal operation it is recommended to only set one key unless you are in the process of rotating keys with the `coder server dbcrypt rotate` command.",
|
||||
|
||||
Reference in New Issue
Block a user