feat: add dynamic group mappings for OIDC (#11656)

Currently, Forgejo supports configuring static group team mappings for
an OIDC authentication source that map OIDC groups to Forgejo
organizations and teams. For example, the following mapping

```json
{"Developer": {"MyForgejoOrganization": ["MyForgejoTeam1", "MyForgejoTeam2"]}}
```

automatically adds a user in the OIDC group `Developer` to the teams
`MyForgejoTeam1` and `MyForgejoTeam2` in organization
`MyForgejoOrganization`.

In order to support more dynamic mappings and to avoid having to update
the mappings for new organizations and teams, add an additional
configuration option that supports mappings with placeholders like in
the following example:

```json
["group-{org}-{team}", "other:{org}/{team}"]
```

In this example, the mappings add a user in OIDC groups
`group-org1-team1`, `group-org2-team2`, and `other:org3/team3` to team
`team1` in organization `org1`, team `team2` in organization `org2`, and
to team `team3` in organization `org3`.

Additionally, this adds a configuration option to dynamically remove
users from organization teams. If enabled, a user is removed from all
teams that are not added via a static or dynamic mapping. Thus, users
are only in teams that are added via such a mapping and no other teams.

Docs: forgejo/docs!1950

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/11656
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
This commit is contained in:
hwipl
2026-05-22 12:38:20 +02:00
committed by Gusted
parent 7054075be5
commit 1ea5605eae
18 changed files with 803 additions and 19 deletions
+13
View File
@@ -22,6 +22,19 @@ func UnmarshalGroupTeamMapping(raw string) (map[string]map[string][]string, erro
return groupTeamMapping, nil
}
func UnmarshalDynGroupMappings(raw string) ([]string, error) {
var dynGroupMappings []string
if raw == "" {
return dynGroupMappings, nil
}
err := json.Unmarshal([]byte(raw), &dynGroupMappings)
if err != nil {
log.Error("Failed to unmarshal dynamic group mappings: %v", err)
return nil, err
}
return dynGroupMappings, nil
}
func UnmarshalQuotaGroupMapping(raw string) (map[string]container.Set[string], error) {
quotaGroupMapping := make(map[string]container.Set[string])
if raw == "" {
+20
View File
@@ -27,6 +27,8 @@ const (
ErrUsername = "UsernameError"
// ErrInvalidGroupTeamMap is returned when a group team mapping is invalid
ErrInvalidGroupTeamMap = "InvalidGroupTeamMap"
// ErrInvalidDynGroupMaps is returned when dynamic group team mappings are invalid
ErrInvalidDynGroupMaps = "InvalidDynGroupMaps"
// ErrInvalidQuotaGroupMap is returned when a quota group mapping is invalid
ErrInvalidQuotaGroupMap = "InvalidQuotaGroupMap"
// ErrEmail is returned when an email address is invalid
@@ -35,6 +37,7 @@ const (
// AddBindingRules adds additional binding rules
func AddBindingRules() {
addValidDynGroupMapsRule()
addGitRefNameBindingRule()
addValidURLListBindingRule()
addValidURLBindingRule()
@@ -220,6 +223,23 @@ func addValidGroupTeamMapRule() {
})
}
func addValidDynGroupMapsRule() {
binding.AddRule(&binding.Rule{
IsMatch: func(rule string) bool {
return rule == "ValidDynGroupMaps"
},
IsValid: func(errs binding.Errors, name string, val any) (bool, binding.Errors) {
_, err := auth.UnmarshalDynGroupMappings(fmt.Sprintf("%v", val))
if err != nil {
errs.Add([]string{name}, ErrInvalidDynGroupMaps, err.Error())
return false, errs
}
return true, errs
},
})
}
func addValidQuotaGroupMapRule() {
binding.AddRule(&binding.Rule{
IsMatch: func(rule string) bool {