Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Multi-Organization Role Sync compatibility upgrade #14203

Closed
Assignees
Emyrk
Labels
enterpriseEnterprise-license / premium functionalitymulti-orgtemporary label for multiple organizations related work
@Emyrk

Description

@Emyrk

Role sync currently only works for site-wide roles. This functionality should remain, with the addition that organization roles can also be assigned.

oidcRoles should return[]rbac.RoleIdentifier rather than[]string to support organizational roles.

Given the "self serve" nature of organizations, org role assignment configuration might want to be deferred to org admins. So the current deployment wide configcould remain, with an organization specific configuration extension.

Some debugging and visual tools to see which roles are available via the IDP would be required.

Deployment configuration to upgrade

Static role mapping

User role mapping is defined as a staticOIDC_Role -> Coder Site Role. We either need to allow an organization context in the existing configuration option, or add a new config field to inject an organization role.

Metadata

Metadata

Assignees

Labels

enterpriseEnterprise-license / premium functionalitymulti-orgtemporary label for multiple organizations related work

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions


    [8]ページ先頭

    ©2009-2025 Movatter.jp