 40a7135c0c
			
		
	
	40a7135c0c
	
	
	
		
			
			* core: initial app entitlements Signed-off-by: Jens Langhammer <jens@goauthentik.io> * base off of pbm Signed-off-by: Jens Langhammer <jens@goauthentik.io> * add tests and oauth2 Signed-off-by: Jens Langhammer <jens@goauthentik.io> * add to proxy Signed-off-by: Jens Langhammer <jens@goauthentik.io> * rewrite to use bindings Signed-off-by: Jens Langhammer <jens@goauthentik.io> * make policy bindings form and list more customizable Signed-off-by: Jens Langhammer <jens@goauthentik.io> * fix tests Signed-off-by: Jens Langhammer <jens@goauthentik.io> * double fix Signed-off-by: Jens Langhammer <jens@goauthentik.io> * refine permissions Signed-off-by: Jens Langhammer <jens@goauthentik.io> * add missing rbac modal to app entitlements Signed-off-by: Jens Langhammer <jens@goauthentik.io> * separate scope for app entitlements Signed-off-by: Jens Langhammer <jens@goauthentik.io> * include entitlements mapping in proxy Signed-off-by: Jens Langhammer <jens@goauthentik.io> * fix tests Signed-off-by: Jens Langhammer <jens@goauthentik.io> * add API validation to prevent policies from being bound to entitlements Signed-off-by: Jens Langhammer <jens@goauthentik.io> * make preview Signed-off-by: Jens Langhammer <jens@goauthentik.io> * add initial docs Signed-off-by: Jens Langhammer <jens@goauthentik.io> * fix Signed-off-by: Jens Langhammer <jens@goauthentik.io> * remove duplicate docs Signed-off-by: Jens Langhammer <jens@goauthentik.io> --------- Signed-off-by: Jens Langhammer <jens@goauthentik.io>
		
			
				
	
	
		
			23 lines
		
	
	
		
			780 B
		
	
	
	
		
			Go
		
	
	
	
	
	
			
		
		
	
	
			23 lines
		
	
	
		
			780 B
		
	
	
	
		
			Go
		
	
	
	
	
	
| package application
 | |
| 
 | |
| type ProxyClaims struct {
 | |
| 	UserAttributes  map[string]interface{} `json:"user_attributes"`
 | |
| 	BackendOverride string                 `json:"backend_override"`
 | |
| 	IsSuperuser     bool                   `json:"is_superuser"`
 | |
| }
 | |
| 
 | |
| type Claims struct {
 | |
| 	Sub               string       `json:"sub"`
 | |
| 	Exp               int          `json:"exp"`
 | |
| 	Email             string       `json:"email"`
 | |
| 	Verified          bool         `json:"email_verified"`
 | |
| 	Name              string       `json:"name"`
 | |
| 	PreferredUsername string       `json:"preferred_username"`
 | |
| 	Groups            []string     `json:"groups"`
 | |
| 	Entitlements      []string     `json:"entitlements"`
 | |
| 	Sid               string       `json:"sid"`
 | |
| 	Proxy             *ProxyClaims `json:"ak_proxy"`
 | |
| 
 | |
| 	RawToken string
 | |
| }
 |