Add OAuth2 API scope registration and enforcement

Register v1 API scopes in coredata, advertise them in OIDC discovery
and protected-resource metadata, show them on the consent screen, and
enforce scope-to-action mapping in the IAM Authorizer before policy
evaluation.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-06-15 17:33:15 +02:00
parent 25151fa089
commit 3ebb221a9b
56 changed files with 1918 additions and 290 deletions

View File

@@ -27,32 +27,12 @@ type (
OAuth2Scopes []OAuth2Scope
)
const (
OAuth2ScopeOpenID OAuth2Scope = "openid"
OAuth2ScopeProfile OAuth2Scope = "profile"
OAuth2ScopeEmail OAuth2Scope = "email"
OAuth2ScopeOfflineAccess OAuth2Scope = "offline_access"
)
var (
_ fmt.Stringer = OAuth2Scope("")
_ encoding.TextMarshaler = OAuth2Scope("")
_ encoding.TextUnmarshaler = (*OAuth2Scope)(nil)
)
func (v OAuth2Scope) IsValid() bool {
switch v {
case
OAuth2ScopeOpenID,
OAuth2ScopeProfile,
OAuth2ScopeEmail,
OAuth2ScopeOfflineAccess:
return true
}
return false
}
func (v OAuth2Scope) String() string {
return string(v)
}
@@ -62,12 +42,7 @@ func (v OAuth2Scope) MarshalText() ([]byte, error) {
}
func (v *OAuth2Scope) UnmarshalText(text []byte) error {
val := OAuth2Scope(text)
if !val.IsValid() {
return fmt.Errorf("invalid OAuth2Scope value: %q", string(text))
}
*v = val
*v = OAuth2Scope(text)
return nil
}