Auth: Add alpha version of the Extended JWT client (#67999)
* initial commit * Add tests, add configuration options * Extend signingkeys.Service with GetServerPublicKey method * Add, cleanup tests * Add tests for entitlements claim * Fix linting errors * Suggestion to use a struct to extend the claims (cherry picked from commit 8078b99f1d57c9426a15693d850c1ca5f0432cbe) * Add requested changes Co-authored-by: Gabriel MABILLE <gamab@users.noreply.github.com> * Add test for orgID check * Cleanup --------- Co-authored-by: Gabriel MABILLE <gamab@users.noreply.github.com>
This commit is contained in:
@@ -315,6 +315,11 @@ type Cfg struct {
|
||||
JWTAuthAllowAssignGrafanaAdmin bool
|
||||
JWTAuthSkipOrgRoleSync bool
|
||||
|
||||
// Extended JWT Auth
|
||||
ExtendedJWTAuthEnabled bool
|
||||
ExtendedJWTExpectIssuer string
|
||||
ExtendedJWTExpectAudience string
|
||||
|
||||
// Dataproxy
|
||||
SendUserHeader bool
|
||||
DataProxyLogging bool
|
||||
@@ -1542,6 +1547,13 @@ func readAuthSettings(iniFile *ini.File, cfg *Cfg) (err error) {
|
||||
cfg.JWTAuthAllowAssignGrafanaAdmin = authJWT.Key("allow_assign_grafana_admin").MustBool(false)
|
||||
cfg.JWTAuthSkipOrgRoleSync = authJWT.Key("skip_org_role_sync").MustBool(false)
|
||||
|
||||
// Extended JWT auth
|
||||
authExtendedJWT := iniFile.Section("auth.extended_jwt")
|
||||
cfg.ExtendedJWTAuthEnabled = authExtendedJWT.Key("enabled").MustBool(false)
|
||||
cfg.ExtendedJWTExpectAudience = authExtendedJWT.Key("expect_audience").MustString("")
|
||||
cfg.ExtendedJWTExpectIssuer = authExtendedJWT.Key("expect_issuer").MustString("")
|
||||
|
||||
// Auth Proxy
|
||||
authProxy := iniFile.Section("auth.proxy")
|
||||
cfg.AuthProxyEnabled = authProxy.Key("enabled").MustBool(false)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user