# yaml-language-server: $schema=https://goauthentik.io/blueprints/schema.json version: 1 metadata: name: haze-nextcloud-saml entries: - model: authentik_crypto.certificatekeypair id: haze-saml-cert identifiers: name: haze-saml attrs: certificate_data: !File /haze/authentik/public.crt key_data: !File /haze/authentik/private.key # Prefix SAML users with 'saml-' so that they don't collide with local users. - model: authentik_providers_saml.samlpropertymapping id: haze-nextcloud-uid identifiers: name: haze-nextcloud-uid attrs: saml_name: http://haze.test/nextcloud/uid expression: 'return "saml-" + request.user.username' # Symbolic name of the Global Scale node the user belongs to, resolved to an # address by the mapping file maintained by haze. - model: authentik_providers_saml.samlpropertymapping id: haze-nextcloud-gss-node identifiers: name: haze-nextcloud-gss-node attrs: saml_name: http://haze.test/nextcloud/gss-node expression: 'return request.user.attributes.get("nextcloud_gss_node", "")' - model: authentik_providers_saml.samlprovider id: nextcloud-provider identifiers: name: nextcloud attrs: acs_url: !Format [ "%s/index.php/apps/user_saml/saml/acs", !File /haze/authentik/nextcloud-url, ] audience: !Format [ "%s/index.php/apps/user_saml/saml/metadata", !File /haze/authentik/nextcloud-url, ] sls_url: !Format [ "%s/index.php/apps/user_saml/saml/sls", !File /haze/authentik/nextcloud-url, ] sls_binding: redirect sp_binding: post issuer_override: !Format [ "%s/application/saml/nextcloud-saml/metadata/", !File /haze/authentik/authentik-url, ] default_name_id_policy: urn:oasis:names:tc:SAML:2.0:nameid-format:persistent assertion_valid_not_before: minutes=-5 assertion_valid_not_on_or_after: minutes=5 session_valid_not_on_or_after: minutes=86400 digest_algorithm: http://www.w3.org/2001/04/xmlenc#sha256 signature_algorithm: http://www.w3.org/2001/04/xmldsig-more#rsa-sha256 sign_assertion: true signing_kp: !KeyOf haze-saml-cert authorization_flow: !Find [ authentik_flows.flow, [slug, default-provider-authorization-implicit-consent], ] invalidation_flow: !Find [authentik_flows.flow, [slug, default-provider-invalidation-flow]] name_id_mapping: !KeyOf haze-nextcloud-uid property_mappings: - !KeyOf haze-nextcloud-uid - !KeyOf haze-nextcloud-gss-node - !Find [ authentik_providers_saml.samlpropertymapping, [managed, goauthentik.io/providers/saml/username], ] - !Find [ authentik_providers_saml.samlpropertymapping, [managed, goauthentik.io/providers/saml/email], ] - !Find [ authentik_providers_saml.samlpropertymapping, [managed, goauthentik.io/providers/saml/name], ] - !Find [ authentik_providers_saml.samlpropertymapping, [managed, goauthentik.io/providers/saml/uid], ] - !Find [ authentik_providers_saml.samlpropertymapping, [managed, goauthentik.io/providers/saml/groups], ] - model: authentik_core.application identifiers: slug: nextcloud-saml attrs: name: Nextcloud with SAML provider: !KeyOf nextcloud-provider meta_launch_url: !File /haze/authentik/nextcloud-url meta_description: Nextcloud instance provisioned by haze