mirror of
				https://github.com/go-gitea/gitea.git
				synced 2025-10-31 21:28:11 +09:00 
			
		
		
		
	Map OIDC groups to Orgs/Teams (#21441)
Fixes #19555 Test-Instructions: https://github.com/go-gitea/gitea/pull/21441#issuecomment-1419438000 This PR implements the mapping of user groups provided by OIDC providers to orgs teams in Gitea. The main part is a refactoring of the existing LDAP code to make it usable from different providers. Refactorings: - Moved the router auth code from module to service because of import cycles - Changed some model methods to take a `Context` parameter - Moved the mapping code from LDAP to a common location I've tested it with Keycloak but other providers should work too. The JSON mapping format is the same as for LDAP.  --------- Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
This commit is contained in:
		
							
								
								
									
										22
									
								
								modules/auth/common.go
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										22
									
								
								modules/auth/common.go
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,22 @@ | ||||
| // Copyright 2022 The Gitea Authors. All rights reserved. | ||||
| // SPDX-License-Identifier: MIT | ||||
|  | ||||
| package auth | ||||
|  | ||||
| import ( | ||||
| 	"code.gitea.io/gitea/modules/json" | ||||
| 	"code.gitea.io/gitea/modules/log" | ||||
| ) | ||||
|  | ||||
| func UnmarshalGroupTeamMapping(raw string) (map[string]map[string][]string, error) { | ||||
| 	groupTeamMapping := make(map[string]map[string][]string) | ||||
| 	if raw == "" { | ||||
| 		return groupTeamMapping, nil | ||||
| 	} | ||||
| 	err := json.Unmarshal([]byte(raw), &groupTeamMapping) | ||||
| 	if err != nil { | ||||
| 		log.Error("Failed to unmarshal group team mapping: %v", err) | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	return groupTeamMapping, nil | ||||
| } | ||||
		Reference in New Issue
	
	Block a user