# yaml-language-server: $schema=https://goauthentik.io/blueprints/schema.json version: 1 metadata: name: haze-nextcloud-oidc entries: - model: authentik_crypto.certificatekeypair id: haze-oidc-cert identifiers: name: haze-oidc attrs: certificate_data: !File /haze/authentik/public.crt key_data: !File /haze/authentik/private.key # Prefix OIDC users with 'oidc-' so that they don't collide with local users. - model: authentik_providers_oauth2.scopemapping id: haze-nextcloud-oidc-uid identifiers: name: haze-nextcloud-oidc-uid attrs: scope_name: nextcloud expression: | return { "nextcloud_uid": "oidc-" + request.user.username, "nextcloud_gss_node": request.user.attributes.get("nextcloud_gss_node", ""), } - model: authentik_providers_oauth2.oauth2provider id: nextcloud-oidc-provider identifiers: name: nextcloud-oidc attrs: client_type: confidential client_id: nextcloud client_secret: haze-oidc-secret grant_types: - authorization_code - refresh_token redirect_uris: - matching_mode: strict url: !Format [ "%s/index.php/apps/user_oidc/code", !File /haze/authentik/nextcloud-url, ] signing_key: !KeyOf haze-oidc-cert authorization_flow: !Find [ authentik_flows.flow, [slug, default-provider-authorization-implicit-consent], ] invalidation_flow: !Find [authentik_flows.flow, [slug, default-provider-invalidation-flow]] property_mappings: - !KeyOf haze-nextcloud-oidc-uid - !Find [ authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-openid], ] - !Find [ authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-email], ] - !Find [ authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-profile], ] - model: authentik_core.application identifiers: slug: nextcloud-oidc attrs: name: Nextcloud with OIDC provider: !KeyOf nextcloud-oidc-provider meta_launch_url: !File /haze/authentik/nextcloud-url meta_description: Nextcloud instance provisioned by haze