mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: add warning log if misconfigured groups oidc (#7874)
* chore: add warning log if misconfigured groups oidc This is not perfect, but if we find a 'groups' claim and it is not configured, put out a warning log to give some information
This commit is contained in:
+10
-1
@@ -231,7 +231,7 @@ CODER_TLS_CLIENT_KEY_FILE=/path/to/key.pem
|
||||
If your OpenID Connect provider supports group claims, you can configure Coder
|
||||
to synchronize groups in your auth provider to groups within Coder.
|
||||
|
||||
To enable group sync, ensure that the `groups` claim is set. If group sync is
|
||||
To enable group sync, ensure that the `groups` claim is set by adding the correct scope to request. If group sync is
|
||||
enabled, the user's groups will be controlled by the OIDC provider. This means
|
||||
manual group additions/removals will be overwritten on the next login.
|
||||
|
||||
@@ -242,6 +242,15 @@ CODER_OIDC_SCOPES=openid,profile,email,groups
|
||||
--oidc-scopes openid,profile,email,groups
|
||||
```
|
||||
|
||||
With the `groups` scope requested, we also need to map the `groups` claim name. Coder recommends using `groups` for the claim name. This step is necessary if your **scope's name** is something other than `groups`.
|
||||
|
||||
```console
|
||||
# as an environment variable
|
||||
CODER_OIDC_GROUP_FIELD=groups
|
||||
# as a flag
|
||||
--oidc-group-field groups
|
||||
```
|
||||
|
||||
On login, users will automatically be assigned to groups that have matching
|
||||
names in Coder and removed from groups that the user no longer belongs to.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user