-
Notifications
You must be signed in to change notification settings - Fork 943
feat: implement organization role sync #14649
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 1 commit
Commits
Show all changes
13 commits
Select commit
Hold shift + click to select a range
9a73013
rolesync start
Emyrk c6080b5
chore: implement organization and site wide role sync in idpsync
Emyrk ca8e9b9
work on unit test for role sync
Emyrk b1ece73
chore: remove resetting user's roles on misconfigured
Emyrk 5d0f729
Begin unit testing work
Emyrk 601652c
test enterprise parse
Emyrk 2a1e2d0
chore: remove old role sync, insert new idpsync package
Emyrk 8967a42
fixup test
Emyrk f51fae7
linting
Emyrk 12c7af7
rebase fixes
Emyrk 8857660
extract method into it's own funciton
Emyrk 7ff0bb0
linting
Emyrk d8b0d45
Trigger Build
Emyrk File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
chore: implement organization and site wide role sync in idpsync
- Loading branch information
commit c6080b5a64164c24e9b30f02b101c54aac6c3784
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
10000
View file
Open in desktop
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,67 @@ | ||
package enidpsync | ||
|
||
import ( | ||
"context" | ||
"fmt" | ||
"net/http" | ||
|
||
"github.com/golang-jwt/jwt/v4" | ||
|
||
"cdr.dev/slog" | ||
"github.com/coder/coder/v2/coderd/idpsync" | ||
"github.com/coder/coder/v2/codersdk" | ||
) | ||
|
||
func (e EnterpriseIDPSync) RoleSyncEnabled() bool { | ||
return e.entitlements.Enabled(codersdk.FeatureUserRoleManagement) | ||
} | ||
|
||
func (e EnterpriseIDPSync) ParseRoleClaims(ctx context.Context, mergedClaims jwt.MapClaims) (idpsync.RoleParams, *idpsync.HTTPError) { | ||
if !e.RoleSyncEnabled() { | ||
return e.AGPLIDPSync.ParseRoleClaims(ctx, mergedClaims) | ||
} | ||
|
||
var claimRoles []string | ||
if e.AGPLIDPSync.SiteRoleField != "" { | ||
var err error | ||
// TODO: Smoke test this error for org and site | ||
claimRoles, err = e.AGPLIDPSync.RolesFromClaim(e.AGPLIDPSync.SiteRoleField, mergedClaims) | ||
if err != nil { | ||
rawType := mergedClaims[e.AGPLIDPSync.SiteRoleField] | ||
e.Logger.Error(ctx, "oidc claims user roles field was an unknown type", | ||
slog.F("type", fmt.Sprintf("%T", rawType)), | ||
slog.F("field", e.AGPLIDPSync.SiteRoleField), | ||
slog.F("raw_value", rawType), | ||
slog.Error(err), | ||
) | ||
// TODO: Deterine a static page or not | ||
return idpsync.RoleParams{}, &idpsync.HTTPError{ | ||
Code: http.StatusInternalServerError, | ||
Msg: "Login disabled until site wide OIDC config is fixed", | ||
Detail: fmt.Sprintf("Roles claim must be an array of strings, type found: %T. Disabling role sync will allow login to proceed.", rawType), | ||
RenderStaticPage: false, | ||
} | ||
} | ||
} | ||
|
||
siteRoles := append([]string{}, e.SiteDefaultRoles...) | ||
for _, role := range claimRoles { | ||
if mappedRoles, ok := e.SiteRoleMapping[role]; ok { | ||
if len(mappedRoles) == 0 { | ||
continue | ||
} | ||
// Mapped roles are added to the list of roles | ||
siteRoles = append(siteRoles, mappedRoles...) | ||
continue | ||
} | ||
// Append as is. | ||
siteRoles = append(siteRoles, role) | ||
} | ||
|
||
return idpsync.RoleParams{ | ||
SyncEnabled: e.RoleSyncEnabled(), | ||
SyncSiteWide: e.AGPLIDPSync.SiteRoleField != "", | ||
SiteWideRoles: siteRoles, | ||
MergedClaims: mergedClaims, | ||
}, nil | ||
} |
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍