oidc groups: expose Groups through the gRPC API
The Groups column is already persisted on users.User (migration 202505141323) and populated from claims.Groups in FromClaim. This makes the value visible through the gRPC/REST surface so external tools (notably Headplane, which is the motivation for storing the claim in the first place) can read group membership without poking at the database. - proto/headscale/v1/user.proto: add `repeated string groups = 9;` with a doc comment describing where the value comes from. - gen/go/headscale/v1/user.pb.go, gen/openapiv2/headscale/v1/headscale.swagger.json: regenerated via `buf generate --template ../buf.gen.yaml -o .. ../proto`. - hscontrol/types/users.go: populate v1.User.Groups in Proto() by decoding the JSON-encoded users.groups column via GetGroups(). - integration/oidc_groups_test.go: drop the sqlite3-via-Execute hack and verify groups through headscale.ListUsers() like every other user-state integration test.
This commit is contained in:
parent
32ea1c1c84
commit
9ca200b6bc
5 changed files with 57 additions and 56 deletions
|
|
@ -32,6 +32,10 @@ type User struct {
|
|||
ProviderId string `protobuf:"bytes,6,opt,name=provider_id,json=providerId,proto3" json:"provider_id,omitempty"`
|
||||
Provider string `protobuf:"bytes,7,opt,name=provider,proto3" json:"provider,omitempty"`
|
||||
ProfilePicUrl string `protobuf:"bytes,8,opt,name=profile_pic_url,json=profilePicUrl,proto3" json:"profile_pic_url,omitempty"`
|
||||
// OIDC group memberships extracted from the identity provider's
|
||||
// `groups` claim at login. Populated by hscontrol/types.User.FromClaim.
|
||||
// External tools (Headplane, automation) use this for role-based access.
|
||||
Groups []string `protobuf:"bytes,9,rep,name=groups,proto3" json:"groups,omitempty"`
|
||||
unknownFields protoimpl.UnknownFields
|
||||
sizeCache protoimpl.SizeCache
|
||||
}
|
||||
|
|
@ -122,6 +126,13 @@ func (x *User) GetProfilePicUrl() string {
|
|||
return ""
|
||||
}
|
||||
|
||||
func (x *User) GetGroups() []string {
|
||||
if x != nil {
|
||||
return x.Groups
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
type CreateUserRequest struct {
|
||||
state protoimpl.MessageState `protogen:"open.v1"`
|
||||
Name string `protobuf:"bytes,1,opt,name=name,proto3" json:"name,omitempty"`
|
||||
|
|
@ -518,7 +529,7 @@ var File_headscale_v1_user_proto protoreflect.FileDescriptor
|
|||
|
||||
const file_headscale_v1_user_proto_rawDesc = "" +
|
||||
"\n" +
|
||||
"\x17headscale/v1/user.proto\x12\fheadscale.v1\x1a\x1fgoogle/protobuf/timestamp.proto\"\x83\x02\n" +
|
||||
"\x17headscale/v1/user.proto\x12\fheadscale.v1\x1a\x1fgoogle/protobuf/timestamp.proto\"\x9b\x02\n" +
|
||||
"\x04User\x12\x0e\n" +
|
||||
"\x02id\x18\x01 \x01(\x04R\x02id\x12\x12\n" +
|
||||
"\x04name\x18\x02 \x01(\tR\x04name\x129\n" +
|
||||
|
|
@ -529,7 +540,8 @@ const file_headscale_v1_user_proto_rawDesc = "" +
|
|||
"\vprovider_id\x18\x06 \x01(\tR\n" +
|
||||
"providerId\x12\x1a\n" +
|
||||
"\bprovider\x18\a \x01(\tR\bprovider\x12&\n" +
|
||||
"\x0fprofile_pic_url\x18\b \x01(\tR\rprofilePicUrl\"\x81\x01\n" +
|
||||
"\x0fprofile_pic_url\x18\b \x01(\tR\rprofilePicUrl\x12\x16\n" +
|
||||
"\x06groups\x18\t \x03(\tR\x06groups\"\x81\x01\n" +
|
||||
"\x11CreateUserRequest\x12\x12\n" +
|
||||
"\x04name\x18\x01 \x01(\tR\x04name\x12!\n" +
|
||||
"\fdisplay_name\x18\x02 \x01(\tR\vdisplayName\x12\x14\n" +
|
||||
|
|
|
|||
|
|
@ -1528,6 +1528,13 @@
|
|||
},
|
||||
"profilePicUrl": {
|
||||
"type": "string"
|
||||
},
|
||||
"groups": {
|
||||
"type": "array",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"description": "OIDC group memberships extracted from the identity provider's\n`groups` claim at login. Populated by hscontrol/types.User.FromClaim.\nExternal tools (Headplane, automation) use this for role-based access."
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue