mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add sourcing secondary claims from access_token (#16517)
Niche edge case, assumes access_token is jwt. Some `access_token`s are JWT's with potential useful claims. These claims would be nearly equivalent to `user_info` claims. This is not apart of the oauth spec, so this feature should not be loudly advertised. If using this feature, alternate solutions are preferred.
This commit is contained in:
+12
-1
@@ -172,6 +172,17 @@ func createOIDCConfig(ctx context.Context, logger slog.Logger, vals *codersdk.De
|
||||
groupAllowList[group] = true
|
||||
}
|
||||
|
||||
secondaryClaimsSrc := coderd.MergedClaimsSourceUserInfo
|
||||
if !vals.OIDC.IgnoreUserInfo && vals.OIDC.UserInfoFromAccessToken {
|
||||
return nil, xerrors.Errorf("to use 'oidc-access-token-claims', 'oidc-ignore-userinfo' must be set to 'false'")
|
||||
}
|
||||
if vals.OIDC.IgnoreUserInfo {
|
||||
secondaryClaimsSrc = coderd.MergedClaimsSourceNone
|
||||
}
|
||||
if vals.OIDC.UserInfoFromAccessToken {
|
||||
secondaryClaimsSrc = coderd.MergedClaimsSourceAccessToken
|
||||
}
|
||||
|
||||
return &coderd.OIDCConfig{
|
||||
OAuth2Config: useCfg,
|
||||
Provider: oidcProvider,
|
||||
@@ -187,7 +198,7 @@ func createOIDCConfig(ctx context.Context, logger slog.Logger, vals *codersdk.De
|
||||
NameField: vals.OIDC.NameField.String(),
|
||||
EmailField: vals.OIDC.EmailField.String(),
|
||||
AuthURLParams: vals.OIDC.AuthURLParams.Value,
|
||||
IgnoreUserInfo: vals.OIDC.IgnoreUserInfo.Value(),
|
||||
SecondaryClaims: secondaryClaimsSrc,
|
||||
SignInText: vals.OIDC.SignInText.String(),
|
||||
SignupsDisabledText: vals.OIDC.SignupsDisabledText.String(),
|
||||
IconURL: vals.OIDC.IconURL.String(),
|
||||
|
||||
+6
@@ -329,6 +329,12 @@ oidc:
|
||||
# Ignore the userinfo endpoint and only use the ID token for user information.
|
||||
# (default: false, type: bool)
|
||||
ignoreUserInfo: false
|
||||
# Source supplemental user claims from the 'access_token'. This assumes the token
|
||||
# is a jwt signed by the same issuer as the id_token. Using this requires setting
|
||||
# 'oidc-ignore-userinfo' to true. This setting is not compliant with the OIDC
|
||||
# specification and is not recommended. Use at your own risk.
|
||||
# (default: false, type: bool)
|
||||
accessTokenClaims: false
|
||||
# This field must be set if using the organization sync feature. Set to the claim
|
||||
# to be used for organizations.
|
||||
# (default: <unset>, type: string)
|
||||
|
||||
Reference in New Issue
Block a user