Documentation
¶
Overview ¶
Package mapper provides claim-based role mapping for PrincipalSource implementations. It allows applications to configure rules that grant internal roles to service identities based on JWT claim values, without requiring the IdP to support custom role claims.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func MatchesValue ¶ added in v0.10.1
MatchesValue reports whether a single claim value satisfies want. val may be a plain string, or an array of strings — []any (as produced by decoding a JSON array claim, e.g. Keycloak's "groups"/"roles" list) or []string. Any other type never matches. want == "*" matches a non-empty string, or a non-empty array; any other want requires an exact match against the string, or against at least one array element.
Exported so other claim-matching implementations in this module (e.g. claimrolemapping's debug-logging mapper) share these exact semantics instead of drifting from them.
Types ¶
type ClaimRoleMapping ¶
type ClaimRoleMapping struct {
// Claims maps claim key → required value.
// Keys may be canonical attribute names (e.g. "primary_email", "username")
// or raw JWT claim names specific to the IdP (e.g. "repository", "app_name").
// A value of "*" matches any non-empty string, or any non-empty array.
//
// The corresponding claim value may be a plain string, or an array (e.g.
// []any, as produced by decoding a JSON array such as Keycloak's "groups"
// or "roles" claim). For an array claim, the predicate matches when want
// equals any one element.
Claims map[string]string
// Role is the role string granted when all claim predicates match.
Role string
}
ClaimRoleMapping maps a set of claim predicates to an internal role. All claim predicates must match (AND semantics).