[PR #1594] [CLOSED] Add OIDC claim names options #2199

Closed
opened 2025-12-29 03:20:11 +01:00 by adam · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/juanfont/headscale/pull/1594
Author: @fen4o
Created: 11/8/2023
Status: Closed

Base: mainHead: add-oidc-claim-names


📝 Commits (1)

  • 9d58489 Add OIDC claim names options

📊 Changes

5 files changed (+248 additions, -14 deletions)

View changed files

📝 CHANGELOG.md (+1 -0)
📝 docs/oidc.md (+5 -0)
📝 hscontrol/oidc.go (+72 -14)
hscontrol/oidc_test.go (+164 -0)
📝 hscontrol/types/config.go (+6 -0)

📄 Description

Some identity providers (auth0 for example) do not allow to set the groups claims (https://auth0.com/docs/secure/tokens/json-web-tokens/create-custom-claims) and administrators must use custom claims names and add them in the id token.

This commit adds the following configuration options:

  • oidc.groups_claim to set the groups claim name
  • oidc.email_claim to set the email claim name

All claims default to the previous values for backwards compatibility.

The groups claim can now also accept []string or string as some providers might return only a string response instead of array.

  • read the CONTRIBUTING guidelines
  • raised a GitHub issue or discussed it on the projects chat beforehand
  • added unit tests
  • added integration tests
  • updated documentation if needed
  • updated CHANGELOG.md

Fixes #1114


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/juanfont/headscale/pull/1594 **Author:** [@fen4o](https://github.com/fen4o) **Created:** 11/8/2023 **Status:** ❌ Closed **Base:** `main` ← **Head:** `add-oidc-claim-names` --- ### 📝 Commits (1) - [`9d58489`](https://github.com/juanfont/headscale/commit/9d5848990348c4107859ed3f5844390d7211a4cd) Add OIDC claim names options ### 📊 Changes **5 files changed** (+248 additions, -14 deletions) <details> <summary>View changed files</summary> 📝 `CHANGELOG.md` (+1 -0) 📝 `docs/oidc.md` (+5 -0) 📝 `hscontrol/oidc.go` (+72 -14) ➕ `hscontrol/oidc_test.go` (+164 -0) 📝 `hscontrol/types/config.go` (+6 -0) </details> ### 📄 Description Some identity providers (auth0 for example) do not allow to set the groups claims (https://auth0.com/docs/secure/tokens/json-web-tokens/create-custom-claims) and administrators must use custom claims names and add them in the id token. This commit adds the following configuration options: - `oidc.groups_claim` to set the groups claim name - `oidc.email_claim` to set the email claim name All claims default to the previous values for backwards compatibility. The groups claim can now also accept `[]string` or `string` as some providers might return only a string response instead of array. <!-- Headscale is "Open Source, acknowledged contribution", this means that any contribution will have to be discussed with the Maintainers before being submitted. This model has been chosen to reduce the risk of burnout by limiting the maintenance overhead of reviewing and validating third-party code. Headscale is open to code contributions for bug fixes without discussion. If you find mistakes in the documentation, please submit a fix to the documentation. --> <!-- Please tick if the following things apply. You… --> - [x] read the [CONTRIBUTING guidelines](README.md#contributing) - [x] raised a GitHub issue or discussed it on the projects chat beforehand - [x] added unit tests - [ ] added integration tests - [x] updated documentation if needed - [ ] updated CHANGELOG.md <!-- If applicable, please reference the issue using `Fixes #XXX` and add tests to cover your new code. --> Fixes #1114 --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
adam added the pull-request label 2025-12-29 03:20:11 +01:00
adam closed this issue 2025-12-29 03:20:11 +01:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/headscale#2199