mod_groups_oidc/mod_groups_oidc.lua
author nicoco <nicoco@nicoco.fr>
Fri, 22 Mar 2024 11:02:04 +0100
changeset 5877 a88c43de648c
parent 5508 7d9dce4e7dd0
permissions -rw-r--r--
mod_privilege: Fix IQ privileges advertising for multiple namespaces Before this fix, the namespaces element were wrongly nested.

local array = require "util.array";

module:add_item("openid-claim", "groups");

local group_memberships = module:open_store("groups", "map");
local function user_groups(username)
	return pairs(group_memberships:get_all(username) or {});
end

module:hook("token/userinfo", function(event)
	local userinfo = event.userinfo;
	if event.claims:contains("groups") then
		userinfo.groups = array(user_groups(event.username));
	end
end);