diff --git a/Template/config/integration.php b/Template/config/integration.php index d21a90c..3733c46 100644 --- a/Template/config/integration.php +++ b/Template/config/integration.php @@ -56,6 +56,11 @@ = $this->form->text('oauth2_custom_group', $values) ?>
= t('Use a comma to enter multiple useable groups: group1,group2 (The referenced groups are handled as external, so existing groups might not work as expected)') ?>
+ = $this->form->label(t('Role Key'), 'oauth2_key_role') ?> + = $this->form->text('oauth2_key_role', $values) ?> += t('Map application role from claim, leave empty when no mapping is wanted. Claim can be a string or array, highest role will be mapped. Available roles: app-admin, app-manager, app-user. Defaults to app-user when no match is found.') ?>
+
= t('Be careful that this claim exists and is properly populated (check if you might need additional scopes for the claim) or you might lock yourself out if you have no local admin accounts!') ?>
= t('Enter the text you would prefer to see rather than the default "OAuth2 login".') ?>
diff --git a/User/GenericOAuth2UserProvider.php b/User/GenericOAuth2UserProvider.php index 7e501fa..20bbc07 100644 --- a/User/GenericOAuth2UserProvider.php +++ b/User/GenericOAuth2UserProvider.php @@ -4,6 +4,7 @@ use Kanboard\Core\Base; use Kanboard\Core\User\UserProviderInterface; +use Kanboard\Core\Security\Role; use Pimple\Container; /** @@ -121,7 +122,24 @@ public function getExternalId() */ public function getRole() { - return ''; + if (empty($this->configModel->get('oauth2_key_role'))) { + return ''; + } + + $userRoles = $this->getKey('oauth2_key_role'); + + if (is_string($userRoles)) { + $userRoles = explode(',', $userRoles); + } + $userRoles = array_map('trim', $userRoles); + + if (in_array(Role::APP_ADMIN, $userRoles)) { + return Role::APP_ADMIN; + } elseif (in_array(Role::APP_MANAGER, $userRoles)) { + return Role::APP_MANAGER; + } + + return Role::APP_USER; } /**