mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: synchronize oidc user roles (#8595)
* feat: oidc user role sync User roles come from oidc claims. Prevent manual user role changes if set. * allow mapping 1:many
This commit is contained in:
@@ -596,6 +596,9 @@ func (r *RootCmd) Server(newAPI func(context.Context, *coderd.Options) (*coderd.
|
||||
IgnoreUserInfo: cfg.OIDC.IgnoreUserInfo.Value(),
|
||||
GroupField: cfg.OIDC.GroupField.String(),
|
||||
GroupMapping: cfg.OIDC.GroupMapping.Value,
|
||||
UserRoleField: cfg.OIDC.UserRoleField.String(),
|
||||
UserRoleMapping: cfg.OIDC.UserRoleMapping.Value,
|
||||
UserRolesDefault: cfg.OIDC.UserRolesDefault.GetSlice(),
|
||||
SignInText: cfg.OIDC.SignInText.String(),
|
||||
IconURL: cfg.OIDC.IconURL.String(),
|
||||
IgnoreEmailVerified: cfg.OIDC.IgnoreEmailVerified.Value(),
|
||||
|
||||
@@ -1095,6 +1095,8 @@ func TestServer(t *testing.T) {
|
||||
require.False(t, deploymentConfig.Values.OIDC.IgnoreUserInfo.Value())
|
||||
require.Empty(t, deploymentConfig.Values.OIDC.GroupField.Value())
|
||||
require.Empty(t, deploymentConfig.Values.OIDC.GroupMapping.Value)
|
||||
require.Empty(t, deploymentConfig.Values.OIDC.UserRoleField.Value())
|
||||
require.Empty(t, deploymentConfig.Values.OIDC.UserRoleMapping.Value)
|
||||
require.Equal(t, "OpenID Connect", deploymentConfig.Values.OIDC.SignInText.Value())
|
||||
require.Empty(t, deploymentConfig.Values.OIDC.IconURL.Value())
|
||||
})
|
||||
|
||||
+14
@@ -337,6 +337,20 @@ can safely ignore these settings.
|
||||
--oidc-scopes string-array, $CODER_OIDC_SCOPES (default: openid,profile,email)
|
||||
Scopes to grant when authenticating with OIDC.
|
||||
|
||||
--oidc-user-role-default string-array, $CODER_OIDC_USER_ROLE_DEFAULT
|
||||
If user role sync is enabled, these roles are always included for all
|
||||
authenticated users. The 'member' role is always assigned.
|
||||
|
||||
--oidc-user-role-field string, $CODER_OIDC_USER_ROLE_FIELD
|
||||
This field must be set if using the user roles sync feature. Set this
|
||||
to the name of the claim used to store the user's role. The roles
|
||||
should be sent as an array of strings.
|
||||
|
||||
--oidc-user-role-mapping struct[map[string][]string], $CODER_OIDC_USER_ROLE_MAPPING (default: {})
|
||||
A map of the OIDC passed in user roles and the groups in Coder it
|
||||
should map to. This is useful if the group names do not match. If
|
||||
mapped to the empty string, the role will ignored.
|
||||
|
||||
--oidc-username-field string, $CODER_OIDC_USERNAME_FIELD (default: preferred_username)
|
||||
OIDC claim field to use as the username.
|
||||
|
||||
|
||||
+4
-2
@@ -15,7 +15,8 @@
|
||||
"display_name": "Owner"
|
||||
}
|
||||
],
|
||||
"avatar_url": ""
|
||||
"avatar_url": "",
|
||||
"login_type": "password"
|
||||
},
|
||||
{
|
||||
"id": "[second user ID]",
|
||||
@@ -28,6 +29,7 @@
|
||||
"[first org ID]"
|
||||
],
|
||||
"roles": [],
|
||||
"avatar_url": ""
|
||||
"avatar_url": "",
|
||||
"login_type": "password"
|
||||
}
|
||||
]
|
||||
|
||||
+14
@@ -268,6 +268,20 @@ oidc:
|
||||
# for when OIDC providers only return group IDs.
|
||||
# (default: {}, type: struct[map[string]string])
|
||||
groupMapping: {}
|
||||
# This field must be set if using the user roles sync feature. Set this to the
|
||||
# name of the claim used to store the user's role. The roles should be sent as an
|
||||
# array of strings.
|
||||
# (default: <unset>, type: string)
|
||||
userRoleField: ""
|
||||
# A map of the OIDC passed in user roles and the groups in Coder it should map to.
|
||||
# This is useful if the group names do not match. If mapped to the empty string,
|
||||
# the role will ignored.
|
||||
# (default: {}, type: struct[map[string][]string])
|
||||
userRoleMapping: {}
|
||||
# If user role sync is enabled, these roles are always included for all
|
||||
# authenticated users. The 'member' role is always assigned.
|
||||
# (default: <unset>, type: string-array)
|
||||
userRoleDefault: []
|
||||
# The text to show on the OpenID Connect sign in button.
|
||||
# (default: OpenID Connect, type: string)
|
||||
signInText: OpenID Connect
|
||||
|
||||
Reference in New Issue
Block a user