mirror of
https://github.com/vmware-tanzu/pinniped.git
synced 2026-09-19 06:31:47 +00:00
Add upstream refresh related config to OIDCIdentityProvider CRD
Also update related docs.
This commit is contained in:
@@ -57,13 +57,22 @@ spec:
|
||||
OIDC identity provider.
|
||||
properties:
|
||||
additionalScopes:
|
||||
description: AdditionalScopes are the scopes in addition to "openid"
|
||||
that will be requested as part of the authorization request
|
||||
flow with an OIDC identity provider. In the case of a Resource
|
||||
Owner Password Credentials Grant flow, AdditionalScopes are
|
||||
the scopes in addition to "openid" that will be requested as
|
||||
part of the token request (see also the allowPasswordGrant field).
|
||||
By default, only the "openid" scope will be requested.
|
||||
description: AdditionalScopes are the additional scopes that will
|
||||
be requested from your OIDC provider in the authorization request
|
||||
during an OIDC Authorization Code Flow and in the token request
|
||||
during a Resource Owner Password Credentials Grant. Note that
|
||||
the "openid" scope will always be requested regardless of the
|
||||
value in this setting, since it is always required according
|
||||
to the OIDC spec. The "offline_access" scope may also be included
|
||||
according to the value of the DoNotRequestOfflineAccess setting.
|
||||
Any other scopes required should be included here in the AdditionalScopes
|
||||
list. For example, you might like to include scopes like "profile",
|
||||
"email", or "groups" in order to receive the related claims
|
||||
in the returned ID token or userinfo endpoint results if you
|
||||
would like to make use of those claims in the OIDCClaims settings
|
||||
to determine the usernames and group memberships of your Kubernetes
|
||||
users. See your OIDC provider's documentation for more information
|
||||
about what scopes are available to request claims.
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
@@ -97,18 +106,98 @@ spec:
|
||||
during Resource Owner Password Credentials Grant logins. AllowPasswordGrant
|
||||
defaults to false.
|
||||
type: boolean
|
||||
doNotRequestOfflineAccess:
|
||||
description: DoNotRequestOfflineAccess determines if the "offline_access"
|
||||
scope will be requested from your OIDC provider in the authorization
|
||||
request during an OIDC Authorization Code Flow and in the token
|
||||
request during a Resource Owner Password Credentials Grant in
|
||||
order to ask to receive a refresh token in the response. Starting
|
||||
in v0.13.0, the Pinniped Supervisor requires that your OIDC
|
||||
provider returns refresh tokens to the Supervisor from these
|
||||
authorization flows. For most OIDC providers, the scope required
|
||||
to receive refresh tokens will be "offline_access". See https://openid.net/specs/openid-connect-core-1_0.html#OfflineAccess
|
||||
for a description of the "offline_access" scope. See the documentation
|
||||
of your OIDC provider's authorization and token endpoints for
|
||||
its requirements for what to include in the request in order
|
||||
to receive a refresh token in the response, if anything. By
|
||||
default, DoNotRequestOfflineAccess is false, which means that
|
||||
"offline_access" will be sent in the authorization request,
|
||||
since that is what is suggested by the OIDC specification. Note
|
||||
that it may be safe to send "offline_access" even to providers
|
||||
which do not require it, since the provider may ignore scopes
|
||||
that it does not understand or require (see https://datatracker.ietf.org/doc/html/rfc6749#section-3.3).
|
||||
In the unusual case that you must avoid sending the "offline_access"
|
||||
scope, set DoNotRequestOfflineAccess to true. This is required
|
||||
if your OIDC provider will reject the request when it includes
|
||||
"offline_access" (e.g. GitLab's OIDC provider). If you need
|
||||
to send some other scope to request a refresh token, include
|
||||
the scope name in the additionalScopes setting. Also note that
|
||||
some OIDC providers may require that the "prompt" param be set
|
||||
to a specific value for the authorization request during an
|
||||
OIDC Authorization Code Flow in order to receive a refresh token
|
||||
in the response. To adjust the prompt param, see the additionalAuthorizeParameters
|
||||
setting.
|
||||
type: boolean
|
||||
extraAuthorizeParameters:
|
||||
description: AdditionalAuthorizeParameters are extra query parameters
|
||||
that should be included in the authorize request to your OIDC
|
||||
provider in the authorization request during an OIDC Authorization
|
||||
Code Flow. By default, no extra parameters are sent. The standard
|
||||
parameters that will be sent are "response_type", "scope", "client_id",
|
||||
"state", "nonce", "code_challenge", "code_challenge_method",
|
||||
and "redirect_uri". These parameters cannot be included in this
|
||||
setting. This setting does not influence the parameters sent
|
||||
to the token endpoint in the Resource Owner Password Credentials
|
||||
Grant. Starting in v0.13.0, the Pinniped Supervisor requires
|
||||
that your OIDC provider returns refresh tokens to the Supervisor
|
||||
from the authorization flows. Some OIDC providers may require
|
||||
a certain value for the "prompt" parameter in order to properly
|
||||
request refresh tokens. See the documentation of your OIDC provider's
|
||||
authorization endpoint for its requirements for what to include
|
||||
in the request in order to receive a refresh token in the response,
|
||||
if anything. If your provider requires the prompt parameter
|
||||
to request a refresh token, then include it here. Also note
|
||||
that most providers also require a certain scope to be requested
|
||||
in order to receive refresh tokens. See the doNotRequestOfflineAccess
|
||||
setting for more information about using scopes to request refresh
|
||||
tokens.
|
||||
items:
|
||||
description: Parameter is a key/value pair which represents
|
||||
a parameter in an HTTP request.
|
||||
properties:
|
||||
name:
|
||||
description: The name of the parameter. Required.
|
||||
minLength: 1
|
||||
type: string
|
||||
value:
|
||||
description: The value of the parameter.
|
||||
type: string
|
||||
required:
|
||||
- name
|
||||
type: object
|
||||
type: array
|
||||
x-kubernetes-list-map-keys:
|
||||
- name
|
||||
x-kubernetes-list-type: map
|
||||
type: object
|
||||
claims:
|
||||
description: Claims provides the names of token claims that will be
|
||||
used when inspecting an identity from this OIDC identity provider.
|
||||
properties:
|
||||
groups:
|
||||
description: Groups provides the name of the token claim that
|
||||
will be used to ascertain the groups to which an identity belongs.
|
||||
description: Groups provides the name of the ID token claim or
|
||||
userinfo endpoint response claim that will be used to ascertain
|
||||
the groups to which an identity belongs. By default, the identities
|
||||
will not include any group memberships when this setting is
|
||||
not configured.
|
||||
type: string
|
||||
username:
|
||||
description: Username provides the name of the token claim that
|
||||
will be used to ascertain an identity's username.
|
||||
description: Username provides the name of the ID token claim
|
||||
or userinfo endpoint response claim that will be used to ascertain
|
||||
an identity's username. When not set, the username will be an
|
||||
automatically constructed unique string which will include the
|
||||
issuer URL of your OIDC provider along with the value of the
|
||||
"sub" (subject) claim from the ID token.
|
||||
type: string
|
||||
type: object
|
||||
client:
|
||||
|
||||
Reference in New Issue
Block a user