mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: support multiple OIDC redirect URIs (#25408)
This PR adds a new opt-in setting, `CODER_OIDC_REDIRECT_ALLOWED_HOSTS`, that lets a single Coder deployment complete OIDC login on more than one hostname. When the allowlist is non-empty, Coder picks the OIDC `redirect_uri` based on the incoming request's Host header (validated against the list) instead of always using the static URL derived from `CODER_ACCESS_URL`. When unset, the (default) behavior is identical to today. The motivation is that a single Coder deployment is frequently reachable via multiple hostnames - for example, an internal hostname for users on a corporate VPN and a different hostname routed through a zero-trust gateway for users off-VPN - but OIDC login today only works on whichever single hostname `CODER_ACCESS_URL` points to, because the `redirect_uri` sent to the IdP is fixed at server startup. Users who reach the deployment on any other valid hostname can see the login page but fail the OIDC callback, since the IdP redirects them back to a hostname they can't reach (or whose cookies they don't have).
This commit is contained in:
+7
@@ -448,6 +448,13 @@ oidc:
|
||||
# enable if you understand and accept the risk.
|
||||
# (default: <unset>, type: bool)
|
||||
dangerousOidcEmailFallback: false
|
||||
# An allowlist of hostnames that may be used as the host of the OIDC redirect_uri.
|
||||
# When set, the redirect_uri sent to the OIDC provider is built from the incoming
|
||||
# request's Host header (validated against this list) instead of from access-url.
|
||||
# Every listed host must also be registered as a valid redirect URI in the OIDC
|
||||
# provider. Ignored when oidc-redirect-url is set.
|
||||
# (default: <unset>, type: string-array)
|
||||
oidcRedirectAllowedHosts: []
|
||||
# Telemetry is critical to our ability to improve Coder. We strip all personal
|
||||
# information before sending data to our servers. Please only disable telemetry
|
||||
# when required by your organization's security policy.
|
||||
|
||||
Reference in New Issue
Block a user