Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions Template/config/integration.php
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,11 @@
<?= $this->form->text('oauth2_custom_group', $values) ?>
<p class="form-help"><?= t('Use a comma to enter multiple useable groups: group1,group2 (The referenced groups are handled as external, so existing groups might not work as expected)') ?></p>

<?= $this->form->label(t('Role Key'), 'oauth2_key_role') ?>
<?= $this->form->text('oauth2_key_role', $values) ?>
<p class="form-help"><?= t('Map application role from claim, leave empty when no mapping is wanted. Claim can be a string or array, highest role will be mapped. Available roles: app-admin, app-manager, app-user. Defaults to app-user when no match is found.') ?>
<br/><?= t('Be careful that this claim exists and is properly populated (check if you might need additional scopes for the claim) or you might lock yourself out if you have no local admin accounts!') ?></p>

<?= $this->form->label(t('Custom Login Text'), 'oauth2_custom_login_text') ?>
<?= $this->form->text('oauth2_custom_login_text', $values) ?>
<p class="form-help"><?= t('Enter the text you would prefer to see rather than the default "OAuth2 login".') ?></p>
Expand Down
20 changes: 19 additions & 1 deletion User/GenericOAuth2UserProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@

use Kanboard\Core\Base;
use Kanboard\Core\User\UserProviderInterface;
use Kanboard\Core\Security\Role;
use Pimple\Container;

/**
Expand Down Expand Up @@ -121,7 +122,24 @@ public function getExternalId()
*/
public function getRole()
{
return '';
if (empty($this->configModel->get('oauth2_key_role'))) {
return '';
}

$userRoles = $this->getKey('oauth2_key_role');

if (is_string($userRoles)) {
$userRoles = explode(',', $userRoles);
}
$userRoles = array_map('trim', $userRoles);

if (in_array(Role::APP_ADMIN, $userRoles)) {
return Role::APP_ADMIN;
} elseif (in_array(Role::APP_MANAGER, $userRoles)) {
return Role::APP_MANAGER;
}

return Role::APP_USER;
}

/**
Expand Down