mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add auto group create from OIDC (#8884)
* add flag for auto create groups * fixup! add flag for auto create groups * sync missing groups Also added a regex filter to filter out groups that are not important
This commit is contained in:
@@ -72,6 +72,40 @@ func TestOptionSet_ParseFlags(t *testing.T) {
|
||||
err := os.FlagSet().Parse([]string{"--some-unknown", "foo"})
|
||||
require.Error(t, err)
|
||||
})
|
||||
|
||||
t.Run("RegexValid", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var regexpString clibase.Regexp
|
||||
|
||||
os := clibase.OptionSet{
|
||||
clibase.Option{
|
||||
Name: "RegexpString",
|
||||
Value: ®expString,
|
||||
Flag: "regexp-string",
|
||||
},
|
||||
}
|
||||
|
||||
err := os.FlagSet().Parse([]string{"--regexp-string", "$test^"})
|
||||
require.NoError(t, err)
|
||||
})
|
||||
|
||||
t.Run("RegexInvalid", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var regexpString clibase.Regexp
|
||||
|
||||
os := clibase.OptionSet{
|
||||
clibase.Option{
|
||||
Name: "RegexpString",
|
||||
Value: ®expString,
|
||||
Flag: "regexp-string",
|
||||
},
|
||||
}
|
||||
|
||||
err := os.FlagSet().Parse([]string{"--regexp-string", "(("})
|
||||
require.Error(t, err)
|
||||
})
|
||||
}
|
||||
|
||||
func TestOptionSet_ParseEnv(t *testing.T) {
|
||||
|
||||
@@ -7,6 +7,7 @@ import (
|
||||
"net"
|
||||
"net/url"
|
||||
"reflect"
|
||||
"regexp"
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
@@ -461,6 +462,43 @@ func (e *Enum) String() string {
|
||||
return *e.Value
|
||||
}
|
||||
|
||||
type Regexp regexp.Regexp
|
||||
|
||||
func (r *Regexp) MarshalYAML() (interface{}, error) {
|
||||
return yaml.Node{
|
||||
Kind: yaml.ScalarNode,
|
||||
Value: r.String(),
|
||||
}, nil
|
||||
}
|
||||
|
||||
func (r *Regexp) UnmarshalYAML(n *yaml.Node) error {
|
||||
return r.Set(n.Value)
|
||||
}
|
||||
|
||||
func (r *Regexp) Set(v string) error {
|
||||
exp, err := regexp.Compile(v)
|
||||
if err != nil {
|
||||
return xerrors.Errorf("invalid regex expression: %w", err)
|
||||
}
|
||||
*r = Regexp(*exp)
|
||||
return nil
|
||||
}
|
||||
|
||||
func (r Regexp) String() string {
|
||||
return r.Value().String()
|
||||
}
|
||||
|
||||
func (r *Regexp) Value() *regexp.Regexp {
|
||||
if r == nil {
|
||||
return nil
|
||||
}
|
||||
return (*regexp.Regexp)(r)
|
||||
}
|
||||
|
||||
func (Regexp) Type() string {
|
||||
return "regexp"
|
||||
}
|
||||
|
||||
var _ pflag.Value = (*YAMLConfigPath)(nil)
|
||||
|
||||
// YAMLConfigPath is a special value type that encodes a path to a YAML
|
||||
|
||||
@@ -597,6 +597,8 @@ func (r *RootCmd) Server(newAPI func(context.Context, *coderd.Options) (*coderd.
|
||||
AuthURLParams: cfg.OIDC.AuthURLParams.Value,
|
||||
IgnoreUserInfo: cfg.OIDC.IgnoreUserInfo.Value(),
|
||||
GroupField: cfg.OIDC.GroupField.String(),
|
||||
GroupFilter: cfg.OIDC.GroupRegexFilter.Value(),
|
||||
CreateMissingGroups: cfg.OIDC.GroupAutoCreate.Value(),
|
||||
GroupMapping: cfg.OIDC.GroupMapping.Value,
|
||||
UserRoleField: cfg.OIDC.UserRoleField.String(),
|
||||
UserRoleMapping: cfg.OIDC.UserRoleMapping.Value,
|
||||
|
||||
+8
@@ -298,6 +298,9 @@ can safely ignore these settings.
|
||||
GitHub.
|
||||
|
||||
[1mOIDC Options[0m
|
||||
--oidc-group-auto-create bool, $CODER_OIDC_GROUP_AUTO_CREATE (default: false)
|
||||
Automatically creates missing groups from a user's groups claim.
|
||||
|
||||
--oidc-allow-signups bool, $CODER_OIDC_ALLOW_SIGNUPS (default: true)
|
||||
Whether new users can sign up with OIDC.
|
||||
|
||||
@@ -334,6 +337,11 @@ can safely ignore these settings.
|
||||
--oidc-issuer-url string, $CODER_OIDC_ISSUER_URL
|
||||
Issuer URL to use for Login with OIDC.
|
||||
|
||||
--oidc-group-regex-filter regexp, $CODER_OIDC_GROUP_REGEX_FILTER (default: .*)
|
||||
If provided any group name not matching the regex is ignored. This
|
||||
allows for filtering out groups that are not needed. This filter is
|
||||
applied after the group mapping.
|
||||
|
||||
--oidc-scopes string-array, $CODER_OIDC_SCOPES (default: openid,profile,email)
|
||||
Scopes to grant when authenticating with OIDC.
|
||||
|
||||
|
||||
+8
@@ -271,6 +271,14 @@ oidc:
|
||||
# for when OIDC providers only return group IDs.
|
||||
# (default: {}, type: struct[map[string]string])
|
||||
groupMapping: {}
|
||||
# Automatically creates missing groups from a user's groups claim.
|
||||
# (default: false, type: bool)
|
||||
enableGroupAutoCreate: false
|
||||
# If provided any group name not matching the regex is ignored. This allows for
|
||||
# filtering out groups that are not needed. This filter is applied after the group
|
||||
# mapping.
|
||||
# (default: .*, type: regexp)
|
||||
groupRegexFilter: .*
|
||||
# This field must be set if using the user roles sync feature. Set this to the
|
||||
# name of the claim used to store the user's role. The roles should be sent as an
|
||||
# array of strings.
|
||||
|
||||
Reference in New Issue
Block a user