1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
use BTreeMap;
use ;
/// Instance-wide policy for the inbound OAuth2 sign-in flow (#307).
///
/// Everything that describes *one* identity-provider relationship — the
/// endpoints, the client credentials, the scopes, PKCE, the state cookie —
/// belongs to the channel's `oauth2_login` block, because it is part of the
/// definition and is promoted with it. What lives here is the operator's egress
/// policy, and (#355) the set of **deployment-supplied providers** — the
/// deliberate exception, for the case the definition cannot express: *which*
/// identity providers exist differs per deployment, and that is a property of
/// the deployment, not the promoted definition.
/// One deployment-supplied identity provider (#355).
///
/// The per-provider half of a channel `oauth2_login` block, expressed in
/// instance TOML. It converts to the one compiled provider shape
/// (`channel::config::ProviderConfig`) at the merge point, so validation and
/// compilation run on a single shape whatever the source.
///
/// OIDC by explicit `id_token` config is not expressible here yet; a
/// deployment-supplied OIDC provider is configured through OIDC discovery
/// (`issuer`) once that lands. `env://NAME` in `client_secret` (and the URL
/// fields) resolves when the channel loads; `${VAR}` anywhere resolves before
/// the file is parsed.