mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-06 22:51:16 +02:00
feat: allow to set non-default authorization request response mode (#3001)
* Update Go version in devcontainer * Add option to change response mode in authorization request * Fix option name * Update docs and changelog * Rename config value to underscore * Add unit tests for added parameter * Move change to upcoming release * Generate alpha config --------- Co-authored-by: Michael Cornel <michael@stieler.it>
This commit is contained in:
@@ -524,6 +524,7 @@ type LegacyProvider struct {
|
||||
OIDCExtraAudiences []string `flag:"oidc-extra-audience" cfg:"oidc_extra_audiences"`
|
||||
OIDCPublicKeyFiles []string `flag:"oidc-public-key-file" cfg:"oidc_public_key_files"`
|
||||
LoginURL string `flag:"login-url" cfg:"login_url"`
|
||||
AuthRequestResponseMode string `flag:"auth-request-response-mode" cfg:"auth_request_response_mode"`
|
||||
RedeemURL string `flag:"redeem-url" cfg:"redeem_url"`
|
||||
ProfileURL string `flag:"profile-url" cfg:"profile_url"`
|
||||
SkipClaimsFromProfileURL bool `flag:"skip-claims-from-profile-url" cfg:"skip_claims_from_profile_url"`
|
||||
@@ -586,6 +587,7 @@ func legacyProviderFlagSet() *pflag.FlagSet {
|
||||
flagSet.String("login-url", "", "Authentication endpoint")
|
||||
flagSet.String("redeem-url", "", "Token redemption endpoint")
|
||||
flagSet.String("profile-url", "", "Profile access endpoint")
|
||||
flagSet.String("auth-request-response-mode", "", "Authorization request response mode")
|
||||
flagSet.Bool("skip-claims-from-profile-url", false, "Skip loading missing claims from profile URL")
|
||||
flagSet.String("resource", "", "The resource that is protected (Azure AD only)")
|
||||
flagSet.String("validate-url", "", "Access token validation endpoint")
|
||||
@@ -684,6 +686,7 @@ func (l *LegacyProvider) convert() (Providers, error) {
|
||||
AllowedGroups: l.AllowedGroups,
|
||||
CodeChallengeMethod: l.CodeChallengeMethod,
|
||||
BackendLogoutURL: l.BackendLogoutURL,
|
||||
AuthRequestResponseMode: l.AuthRequestResponseMode,
|
||||
}
|
||||
|
||||
// This part is out of the switch section for all providers that support OIDC
|
||||
|
||||
@@ -68,6 +68,8 @@ type Provider struct {
|
||||
LoginURL string `json:"loginURL,omitempty"`
|
||||
// LoginURLParameters defines the parameters that can be passed from the start URL to the IdP login URL
|
||||
LoginURLParameters []LoginURLParameter `json:"loginURLParameters,omitempty"`
|
||||
// AuthRequestResponseMode defines the response mode to request during authorization request
|
||||
AuthRequestResponseMode string `json:"authRequestResponseMode,omitempty"`
|
||||
// RedeemURL is the token redemption endpoint
|
||||
RedeemURL string `json:"redeemURL,omitempty"`
|
||||
// ProfileURL is the profile access endpoint
|
||||
|
||||
Reference in New Issue
Block a user