@@ -253,18 +253,26 @@ type TailscaleConfig struct {
253253// OAuth/OIDC config
254254
255255type OAuthServiceConfig struct {
256- ClientID string `description:"OAuth client ID." yaml:"clientId,omitempty"`
257- ClientSecret string `description:"OAuth client secret." yaml:"clientSecret,omitempty"`
258- ClientSecretFile string `description:"Path to the file containing the OAuth client secret." yaml:"clientSecretFile,omitempty"`
259- Whitelist []string `description:"Comma-separated list of allowed OAuth domains for this provider." yaml:"whitelist,omitempty"`
260- WhitelistFile string `description:"Path to the OAuth whitelist file for this provider." yaml:"whitelistFile,omitempty"`
261- Scopes []string `description:"OAuth scopes." yaml:"scopes,omitempty"`
262- RedirectURL string `description:"OAuth redirect URL." yaml:"redirectUrl,omitempty"`
263- AuthURL string `description:"OAuth authorization URL." yaml:"authUrl,omitempty"`
264- TokenURL string `description:"OAuth token URL." yaml:"tokenUrl,omitempty"`
265- UserinfoURL string `description:"OAuth userinfo URL." yaml:"userinfoUrl,omitempty"`
266- Insecure bool `description:"Allow insecure OAuth connections." yaml:"insecure,omitempty"`
267- Name string `description:"Provider name in UI." yaml:"name,omitempty"`
256+ ClientID string `description:"OAuth client ID." yaml:"clientId,omitempty"`
257+ ClientSecret string `description:"OAuth client secret." yaml:"clientSecret,omitempty"`
258+ ClientSecretFile string `description:"Path to the file containing the OAuth client secret." yaml:"clientSecretFile,omitempty"`
259+ Whitelist []string `description:"Comma-separated list of allowed OAuth domains for this provider." yaml:"whitelist,omitempty"`
260+ WhitelistFile string `description:"Path to the OAuth whitelist file for this provider." yaml:"whitelistFile,omitempty"`
261+ Scopes []string `description:"OAuth scopes." yaml:"scopes,omitempty"`
262+ RedirectURL string `description:"OAuth redirect URL." yaml:"redirectUrl,omitempty"`
263+ AuthURL string `description:"OAuth authorization URL." yaml:"authUrl,omitempty"`
264+ TokenURL string `description:"OAuth token URL." yaml:"tokenUrl,omitempty"`
265+ UserinfoURL string `description:"OAuth userinfo URL." yaml:"userinfoUrl,omitempty"`
266+ Insecure bool `description:"Allow insecure OAuth connections." yaml:"insecure,omitempty"`
267+ Name string `description:"Provider name in UI." yaml:"name,omitempty"`
268+ Claims OAuthServiceClaimsMap `description:"Map of claims to extract from the userinfo response." yaml:"claims,omitempty"`
269+ }
270+
271+ type OAuthServiceClaimsMap struct {
272+ Username string `description:"Username claim." yaml:"username,omitempty"`
273+ Email string `description:"Email claim." yaml:"email,omitempty"`
274+ Name string `description:"Name claim." yaml:"name,omitempty"`
275+ Groups string `description:"Groups claim." yaml:"groups,omitempty"`
268276}
269277
270278type OIDCClientConfig struct {
0 commit comments