Repository navigation
Conversation
A UserInfo profile is used only when its sub matches the ID token's; a supplied ID token that does not decode or carries no sub is declined instead of being treated as absent; sub and email count only as non-empty strings; and emailVerified is a boolean on both paths, true only for a literal true claim. The rejection test builds a fresh discovery response per case and creates its rejections only when fetch is called, and asserts the number of requests each case makes.
|
Thanks @askalf! @RhysSullivan can we can include this in the next patch release. |
|
I cut the tests down to make this easier to review.
I also added the changeset the PR template asks for ( Happy to reshape it if you'd like it another way. |
|
We're clearing the backlog ahead of the v2 launch, so we're closing this. If it still applies to v2, please open a new issue or PR against v2. Sent from my Claude |
Summary
A thin OIDC ID token can omit
email_verified, which the self-hosted SSO callback needs to admit a user.ssoProviderConfignow suppliesgetUserInfo, so the claim is read from the provider's UserInfo endpoint when the ID token lacks it.submatches the ID token'ssub. A supplied ID token that does not decode, or has nosub, is declined.emailVerifiedistrueonly for a literaltrueclaim. An explicitfalsein the ID token is honoured without a UserInfo lookup.nullinstead of rejecting the callback.Linked issue
Fixes #1972
Verification
apps/host-selfhost/src/auth/sso-userinfo.test.tshas one case: a thin ID token withemailbut noemail_verifiedis resolved through UserInfo and admitted at the gate.vitest run src/auth/sso-userinfo.test.tsinapps/host-selfhostfails onmainwithTypeError: ssoProviderConfig(...).getUserInfo is not a functionand passes with the fix. The Okta emulator always signsemail_verifiedinto its ID tokens, so the test stubs the two IdP responses.oxfmt --checkandoxlint --deny-warningsare clean on the touched files.Changeset:
.changeset/selfhost-sso-userinfo.md(patch for@executor-js/host-selfhostandexecutor).