mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add endpoint and CLI for users to view their own OIDC claims (#23053)
- Adds a new API endpoint `GET /api/v2/users/oidc-claims` that returns only the **merged claims** (not the separate id_token/userinfo breakdown). Scoped exclusively to the authenticated user's own identity — no user parameter, so users cannot view each other's claims. - Adds a new CLI command:** `coder users oidc-claims` that hits the above endpoint. - The existing owner-only debug endpoint is preserved unchanged for admins who need the full claim breakdown. > 🤖 This PR was created with the help of Coder Agents, and will be reviewed by my human. 🧑💻
This commit is contained in:
Generated
+14
@@ -4339,6 +4339,20 @@ export interface OIDCAuthMethod extends AuthMethod {
|
||||
readonly iconUrl: string;
|
||||
}
|
||||
|
||||
// From codersdk/users.go
|
||||
/**
|
||||
* OIDCClaimsResponse represents the merged OIDC claims for a user.
|
||||
*/
|
||||
export interface OIDCClaimsResponse {
|
||||
/**
|
||||
* Claims are the merged claims from the OIDC provider. These
|
||||
* are the union of the ID token claims and the userinfo claims,
|
||||
* where userinfo claims take precedence on conflict.
|
||||
*/
|
||||
// empty interface{} type, falling back to unknown
|
||||
readonly claims: Record<string, unknown>;
|
||||
}
|
||||
|
||||
// From codersdk/deployment.go
|
||||
export interface OIDCConfig {
|
||||
readonly allow_signups: boolean;
|
||||
|
||||
Reference in New Issue
Block a user