oidc groups: expose Groups through the gRPC API
The Groups column is already persisted on users.User (migration 202505141323) and populated from claims.Groups in FromClaim. This makes the value visible through the gRPC/REST surface so external tools (notably Headplane, which is the motivation for storing the claim in the first place) can read group membership without poking at the database. - proto/headscale/v1/user.proto: add `repeated string groups = 9;` with a doc comment describing where the value comes from. - gen/go/headscale/v1/user.pb.go, gen/openapiv2/headscale/v1/headscale.swagger.json: regenerated via `buf generate --template ../buf.gen.yaml -o .. ../proto`. - hscontrol/types/users.go: populate v1.User.Groups in Proto() by decoding the JSON-encoded users.groups column via GetGroups(). - integration/oidc_groups_test.go: drop the sqlite3-via-Execute hack and verify groups through headscale.ListUsers() like every other user-state integration test.
This commit is contained in:
parent
32ea1c1c84
commit
9ca200b6bc
5 changed files with 57 additions and 56 deletions
|
|
@ -13,6 +13,10 @@ message User {
|
|||
string provider_id = 6;
|
||||
string provider = 7;
|
||||
string profile_pic_url = 8;
|
||||
// OIDC group memberships extracted from the identity provider's
|
||||
// `groups` claim at login. Populated by hscontrol/types.User.FromClaim.
|
||||
// External tools (Headplane, automation) use this for role-based access.
|
||||
repeated string groups = 9;
|
||||
}
|
||||
|
||||
message CreateUserRequest {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue