mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add auto group create from OIDC (#8884)
* add flag for auto create groups * fixup! add flag for auto create groups * sync missing groups Also added a regex filter to filter out groups that are not important
This commit is contained in:
@@ -271,6 +271,8 @@ type OIDCConfig struct {
|
||||
EmailField clibase.String `json:"email_field" typescript:",notnull"`
|
||||
AuthURLParams clibase.Struct[map[string]string] `json:"auth_url_params" typescript:",notnull"`
|
||||
IgnoreUserInfo clibase.Bool `json:"ignore_user_info" typescript:",notnull"`
|
||||
GroupAutoCreate clibase.Bool `json:"group_auto_create" typescript:",notnull"`
|
||||
GroupRegexFilter clibase.Regexp `json:"group_regex_filter" typescript:",notnull"`
|
||||
GroupField clibase.String `json:"groups_field" typescript:",notnull"`
|
||||
GroupMapping clibase.Struct[map[string]string] `json:"group_mapping" typescript:",notnull"`
|
||||
UserRoleField clibase.String `json:"user_role_field" typescript:",notnull"`
|
||||
@@ -1066,6 +1068,26 @@ when required by your organization's security policy.`,
|
||||
Group: &deploymentGroupOIDC,
|
||||
YAML: "groupMapping",
|
||||
},
|
||||
{
|
||||
Name: "Enable OIDC Group Auto Create",
|
||||
Description: "Automatically creates missing groups from a user's groups claim.",
|
||||
Flag: "oidc-group-auto-create",
|
||||
Env: "CODER_OIDC_GROUP_AUTO_CREATE",
|
||||
Default: "false",
|
||||
Value: &c.OIDC.GroupAutoCreate,
|
||||
Group: &deploymentGroupOIDC,
|
||||
YAML: "enableGroupAutoCreate",
|
||||
},
|
||||
{
|
||||
Name: "OIDC Regex Group Filter",
|
||||
Description: "If provided any group name not matching the regex is ignored. This allows for filtering out groups that are not needed. This filter is applied after the group mapping.",
|
||||
Flag: "oidc-group-regex-filter",
|
||||
Env: "CODER_OIDC_GROUP_REGEX_FILTER",
|
||||
Default: ".*",
|
||||
Value: &c.OIDC.GroupRegexFilter,
|
||||
Group: &deploymentGroupOIDC,
|
||||
YAML: "groupRegexFilter",
|
||||
},
|
||||
{
|
||||
Name: "OIDC User Role Field",
|
||||
Description: "This field must be set if using the user roles sync feature. Set this to the name of the claim used to store the user's role. The roles should be sent as an array of strings.",
|
||||
|
||||
+15
-7
@@ -10,6 +10,13 @@ import (
|
||||
"golang.org/x/xerrors"
|
||||
)
|
||||
|
||||
type GroupSource string
|
||||
|
||||
const (
|
||||
GroupSourceUser GroupSource = "user"
|
||||
GroupSourceOIDC GroupSource = "oidc"
|
||||
)
|
||||
|
||||
type CreateGroupRequest struct {
|
||||
Name string `json:"name"`
|
||||
DisplayName string `json:"display_name"`
|
||||
@@ -18,13 +25,14 @@ type CreateGroupRequest struct {
|
||||
}
|
||||
|
||||
type Group struct {
|
||||
ID uuid.UUID `json:"id" format:"uuid"`
|
||||
Name string `json:"name"`
|
||||
DisplayName string `json:"display_name"`
|
||||
OrganizationID uuid.UUID `json:"organization_id" format:"uuid"`
|
||||
Members []User `json:"members"`
|
||||
AvatarURL string `json:"avatar_url"`
|
||||
QuotaAllowance int `json:"quota_allowance"`
|
||||
ID uuid.UUID `json:"id" format:"uuid"`
|
||||
Name string `json:"name"`
|
||||
DisplayName string `json:"display_name"`
|
||||
OrganizationID uuid.UUID `json:"organization_id" format:"uuid"`
|
||||
Members []User `json:"members"`
|
||||
AvatarURL string `json:"avatar_url"`
|
||||
QuotaAllowance int `json:"quota_allowance"`
|
||||
Source GroupSource `json:"source"`
|
||||
}
|
||||
|
||||
func (c *Client) CreateGroup(ctx context.Context, orgID uuid.UUID, req CreateGroupRequest) (Group, error) {
|
||||
|
||||
Reference in New Issue
Block a user