mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-05 14:11:14 +02:00
feat: added organizationId/employee id as preferred username (#3237)
Signed-off-by: Drew Foehn <drew@pixelburn.net> Signed-off-by: Jan Larwig <jan@larwig.com>
This commit is contained in:
@@ -510,6 +510,8 @@ type LegacyProvider struct {
|
||||
GoogleServiceAccountJSON string `flag:"google-service-account-json" cfg:"google_service_account_json"`
|
||||
GoogleUseApplicationDefaultCredentials bool `flag:"google-use-application-default-credentials" cfg:"google_use_application_default_credentials"`
|
||||
GoogleTargetPrincipal string `flag:"google-target-principal" cfg:"google_target_principal"`
|
||||
GoogleUseOrganizationID bool `flag:"google-use-organization-id" cfg:"google_use_organization_id"`
|
||||
GoogleAdminAPIUserScope string `flag:"google-admin-api-user-scope" cfg:"google_admin_api_user_scope"`
|
||||
|
||||
// These options allow for other providers besides Google, with
|
||||
// potential overrides.
|
||||
@@ -623,6 +625,8 @@ func legacyGoogleFlagSet() *pflag.FlagSet {
|
||||
flagSet.String("google-service-account-json", "", "the path to the service account json credentials")
|
||||
flagSet.String("google-use-application-default-credentials", "", "use application default credentials instead of service account json (i.e. GKE Workload Identity)")
|
||||
flagSet.String("google-target-principal", "", "the target principal to impersonate when using ADC")
|
||||
flagSet.String("google-use-organization-id", "", "use organization id as preferred username")
|
||||
flagSet.String("google-admin-api-user-scope", "", "authorization scope required to call users.get, can be one of ")
|
||||
|
||||
return flagSet
|
||||
}
|
||||
@@ -770,6 +774,8 @@ func (l *LegacyProvider) convert() (Providers, error) {
|
||||
ServiceAccountJSON: l.GoogleServiceAccountJSON,
|
||||
UseApplicationDefaultCredentials: l.GoogleUseApplicationDefaultCredentials,
|
||||
TargetPrincipal: l.GoogleTargetPrincipal,
|
||||
UseOrganizationID: l.GoogleUseOrganizationID,
|
||||
AdminAPIUserScope: l.GoogleAdminAPIUserScope,
|
||||
}
|
||||
case "entra-id":
|
||||
provider.MicrosoftEntraIDConfig = MicrosoftEntraIDOptions{
|
||||
|
||||
@@ -230,6 +230,10 @@ type GoogleOptions struct {
|
||||
UseApplicationDefaultCredentials bool `json:"useApplicationDefaultCredentials,omitempty"`
|
||||
// TargetPrincipal is the Google Service Account used for Application Default Credentials
|
||||
TargetPrincipal string `json:"targetPrincipal,omitempty"`
|
||||
// UseOrganizationId indicates whether to use the organization ID as the UserName claim
|
||||
UseOrganizationID bool `json:"useOrganizationID,omitempty"`
|
||||
// admin scope needed for fetching user organization information from admin api, can be one of cloud, user or defaults to readonly
|
||||
AdminAPIUserScope string `json:"adminAPIUserScope,omitempty"`
|
||||
}
|
||||
|
||||
type OIDCOptions struct {
|
||||
|
||||
Reference in New Issue
Block a user