mirror of
https://codeberg.org/icewind/haze.git
synced 2026-10-01 08:44:09 +02:00
feat(service): Add SCIM sync for Teams
Signed-off-by: Louis Chmn <louis@chmn.me>
This commit is contained in:
parent
b38cbbe7ba
commit
188a26ab2d
5 changed files with 139 additions and 1 deletions
|
|
@ -1,8 +1,10 @@
|
|||
mod oidc;
|
||||
mod saml;
|
||||
mod scim;
|
||||
|
||||
pub use oidc::AuthentikOidc;
|
||||
pub use saml::AuthentikSaml;
|
||||
pub use scim::AuthentikScim;
|
||||
|
||||
use crate::Result;
|
||||
use crate::cloud::CloudOptions;
|
||||
|
|
|
|||
73
src/service/authentik/scim.rs
Normal file
73
src/service/authentik/scim.rs
Normal file
|
|
@ -0,0 +1,73 @@
|
|||
use super::{AUTHENTIK_PORT, container_ip, container_name, write_file};
|
||||
use crate::Result;
|
||||
use crate::cloud::CloudOptions;
|
||||
use crate::config::{HazeConfig, ProxyConfig};
|
||||
use crate::service::{ServiceTrait, split_cmnd};
|
||||
use bollard::Docker;
|
||||
|
||||
const BLUEPRINT: &str = include_str!("../../../blueprints/authentik-scim.yaml");
|
||||
|
||||
#[derive(Debug, Clone, Eq, PartialEq)]
|
||||
pub struct AuthentikScim;
|
||||
|
||||
#[async_trait::async_trait]
|
||||
impl ServiceTrait for AuthentikScim {
|
||||
fn name(&self) -> &str {
|
||||
"scim"
|
||||
}
|
||||
|
||||
async fn spawn(
|
||||
&self,
|
||||
_docker: &Docker,
|
||||
cloud_id: &str,
|
||||
_network: &str,
|
||||
config: &HazeConfig,
|
||||
_options: &CloudOptions,
|
||||
) -> Result<Vec<String>> {
|
||||
let blueprints_directory = config
|
||||
.work_dir
|
||||
.join(cloud_id)
|
||||
.join("authentik")
|
||||
.join("blueprints");
|
||||
write_file(&blueprints_directory, "scim.yaml", BLUEPRINT)?;
|
||||
|
||||
Ok(Vec::new())
|
||||
}
|
||||
|
||||
fn apps(&self) -> &'static [&'static str] {
|
||||
&["circles"]
|
||||
}
|
||||
|
||||
async fn post_setup(
|
||||
&self,
|
||||
docker: &Docker,
|
||||
cloud_id: &str,
|
||||
config: &HazeConfig,
|
||||
) -> Result<Vec<Vec<String>>> {
|
||||
let authentik_container = container_name(cloud_id, "server");
|
||||
let authentik_url = config.proxy.addr_with_port(
|
||||
&authentik_container,
|
||||
container_ip(docker, &authentik_container, None).await?,
|
||||
AUTHENTIK_PORT,
|
||||
);
|
||||
|
||||
Ok(vec![
|
||||
split_cmnd("occ config:app:set --silent circles scim_enabled --type boolean --value 1"),
|
||||
split_cmnd(&format!(
|
||||
"occ config:app:set --silent circles scim_endpoint --value {authentik_url}/source/scim/nextcloud-scim/v2"
|
||||
)),
|
||||
split_cmnd("occ config:app:set --silent circles scim_token --value haze-scim-token"),
|
||||
])
|
||||
}
|
||||
|
||||
async fn start_message(
|
||||
&self,
|
||||
_docker: &Docker,
|
||||
cloud_id: &str,
|
||||
_proxy: &ProxyConfig,
|
||||
) -> Result<Option<String>> {
|
||||
Ok(Some(format!(
|
||||
"Once Authentik as started, you can sync teams with 'haze {cloud_id} occ circles:scim:sync-circles'\n",
|
||||
)))
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue