The Groups column is already persisted on users.User (migration
202505141323) and populated from claims.Groups in FromClaim. This
makes the value visible through the gRPC/REST surface so external
tools (notably Headplane, which is the motivation for storing the
claim in the first place) can read group membership without
poking at the database.
- proto/headscale/v1/user.proto: add `repeated string groups = 9;`
with a doc comment describing where the value comes from.
- gen/go/headscale/v1/user.pb.go,
gen/openapiv2/headscale/v1/headscale.swagger.json: regenerated
via `buf generate --template ../buf.gen.yaml -o .. ../proto`.
- hscontrol/types/users.go: populate v1.User.Groups in Proto() by
decoding the JSON-encoded users.groups column via GetGroups().
- integration/oidc_groups_test.go: drop the sqlite3-via-Execute hack
and verify groups through headscale.ListUsers() like every other
user-state integration test.