feat(oidc): make OIDC GetIdentifier claim configurable#712
Open
geonux wants to merge 2 commits into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
name: Pull request
about: Pull request for this project
title: feat(oidc): make OIDC identifier claim configurable
labels: oidc, sub, user_isolation
assignees: ""
Issue/Feature
This PR introduces support for configuring which OIDC claim is used to build the authenticated user identifier returned by
GetIdentifier().Previously, identifier behavior was tied to user-facing fields (historically
preferred_usernamewith fallback toemail). This was not always appropriate for all identity providers and use cases.Additional Information
What changed
uidClaim) in OIDC auth provider configuration.preferred_usernameexists, it is usedemailUid.Note : also a little correction on the MakeFile because of a signature error when unpacking
golangci-lint.Why
We do not always want to rely on email or preferred_username because these are user-facing attributes that may change.
For identity-sensitive logic, a stable and unique value (for example
subor another immutable claim) is often required.Making GetIdentifier() configurable in OIDC context improves:
How this helps functional behavior :
Verification Steps
uidClaim: preferred_username.preferred_usernamepresent.GetIdentifier()resolves topreferred_username.preferred_usernameis missing.emailstill occurs.uidClaim: sub(or another custom claim present in token claims).GetIdentifier()resolves to that custom claim value.Checklist: