Files
tailscale/internal/client/tailscale/identityfederation.go
T
Mario MinardiandMario Minardi c8ae72b537 various: change OAuth and WIF auth key resolvers to take struct args
Change signature of OAuth and identityfederation auth key resolution
hooks to take in structs instead of lists of args as they were getting
unwieldily.

Updates https://github.com/tailscale/tailscale/issues/20339

Signed-off-by: Mario Minardi <mario@tailscale.com>
2026-07-21 15:44:45 -06:00

41 lines
1.5 KiB
Go

// Copyright (c) Tailscale Inc & contributors
// SPDX-License-Identifier: BSD-3-Clause
package tailscale
import (
"context"
"tailscale.com/feature"
)
type ResolveAuthKeyWIFArgs struct {
// BaseURL is the URL of the control server used for token exchange and authkey generation.
BaseURL string
// ClientID is the federated client ID used for token exchange.
ClientID string
// IDToken is the Identity token from the identity provider.
IDToken string
// Audience is the federated audience acquired by configuring the trust credential in the admin UI.
Audience string
// Tags is the list of tags to be associated with the auth key.
Tags []string
}
type ExchangeJWTForTokenWIFArgs struct {
// BaseURL is the URL of the control server used for token exchange.
BaseURL string
// ClientID is the federated client ID used for token exchange.
ClientID string
// IDToken is a JWT identity token to use in the token exchange operation.
IDToken string
}
// HookResolveAuthKeyViaWIF resolves to [identityfederation.resolveAuthKey] when the
// corresponding feature tag is enabled in the build process.
var HookResolveAuthKeyViaWIF feature.Hook[func(ctx context.Context, args ResolveAuthKeyWIFArgs) (string, error)]
// HookExchangeJWTForTokenViaWIF resolves to [identityfederation.exchangeJWTForToken] when the
// corresponding feature tag is enabled in the build process.
var HookExchangeJWTForTokenViaWIF feature.Hook[func(ctx context.Context, arg ExchangeJWTForTokenWIFArgs) (string, error)]