Derive group name from filename; use distinct ak_groups claim
- Permission/role group name now comes from the config filename (the map key), dropping the redundant `name` field from each YAML and the object types. - The hierarchical mapping emits an `ak_groups` claim (scope `ak_groups`) instead of `groups`, so it never collides with the direct-groups the default profile mapping already emits under `groups` (Authentik overrides same-key claims in an unpredictable order). Apps request the `ak_groups` scope and read that claim.
This commit is contained in:
+12
-11
@@ -12,7 +12,7 @@ resource "authentik_group" "this" {
|
||||
resource "authentik_group" "permission" {
|
||||
for_each = var.permission_groups
|
||||
|
||||
name = each.value.name
|
||||
name = each.key
|
||||
attributes = jsonencode(each.value.attributes)
|
||||
}
|
||||
|
||||
@@ -23,21 +23,22 @@ resource "authentik_group" "permission" {
|
||||
resource "authentik_group" "role" {
|
||||
for_each = var.role_groups
|
||||
|
||||
name = each.value.name
|
||||
name = each.key
|
||||
is_superuser = each.value.is_superuser
|
||||
parents = [for p in each.value.permissions : authentik_group.permission[p].id]
|
||||
attributes = jsonencode(each.value.attributes)
|
||||
}
|
||||
|
||||
# Expand the OIDC `groups` claim to include inherited (ancestor) groups. The
|
||||
# default profile mapping only emits direct groups (goauthentik/authentik#15579),
|
||||
# so a member of a role group would not see the permission groups it nests. This
|
||||
# walks each of the user's direct groups up through `.parents` and emits the full
|
||||
# set of names, so role -> permission nesting drives in-app roles. Only evaluated
|
||||
# when a provider requests the `groups` scope.
|
||||
# Emit an `ak_groups` claim containing the user's groups AND all inherited
|
||||
# (ancestor) groups, so role -> permission nesting reaches apps. The default
|
||||
# profile mapping only emits *direct* groups under `groups`
|
||||
# (goauthentik/authentik#15579); we use a distinct claim key so there is no
|
||||
# collision with that (Authentik dict-overrides same-key claims in an
|
||||
# unpredictable order). Apps request the `ak_groups` scope and read the
|
||||
# `ak_groups` claim. Walks each direct group up through `.parents`.
|
||||
resource "authentik_property_mapping_provider_scope" "groups_hierarchical" {
|
||||
name = "unkin: groups (hierarchical)"
|
||||
scope_name = "groups"
|
||||
name = "unkin: ak_groups (hierarchical)"
|
||||
scope_name = "ak_groups"
|
||||
expression = <<-EOT
|
||||
groups = {}
|
||||
pending = list(user.ak_groups.all())
|
||||
@@ -47,7 +48,7 @@ resource "authentik_property_mapping_provider_scope" "groups_hierarchical" {
|
||||
continue
|
||||
groups[grp.pk] = grp.name
|
||||
pending += list(grp.parents.all())
|
||||
return {"groups": sorted(groups.values())}
|
||||
return {"ak_groups": sorted(groups.values())}
|
||||
EOT
|
||||
}
|
||||
|
||||
|
||||
@@ -16,9 +16,9 @@ variable "groups" {
|
||||
# role is an effective member of every permission it grants (Authentik membership
|
||||
# propagates child -> parent). Split into two variables/resources so roles can
|
||||
# reference permission group ids without the authentik_group self-reference error.
|
||||
# The group name is the map key (the config filename); no `name` field needed.
|
||||
variable "permission_groups" {
|
||||
type = map(object({
|
||||
name = string
|
||||
# slug of the oauth2 application this permission grants *access* to; when set,
|
||||
# a policy binding is created gating that app to this group (and its children).
|
||||
application = optional(string, null)
|
||||
@@ -29,7 +29,6 @@ variable "permission_groups" {
|
||||
|
||||
variable "role_groups" {
|
||||
type = map(object({
|
||||
name = string
|
||||
# keys into var.permission_groups that this role nests (becomes its parents).
|
||||
permissions = optional(list(string), [])
|
||||
is_superuser = optional(bool, false)
|
||||
|
||||
Reference in New Issue
Block a user