Browse Source

Merge 5a4b7010a5 into 67957f3c3e

pull/7886/merge
Thomas Kaul 1 day ago
committed by GitHub
parent
commit
7addce3462
No known key found for this signature in database GPG Key ID: B5690EEEBB952194
  1. 4
      CHANGELOG.md
  2. 9
      apps/api/src/app/auth/auth.module.ts
  3. 20
      apps/api/src/app/auth/oidc.helper.spec.ts
  4. 4
      apps/api/src/app/auth/oidc.helper.ts

4
CHANGELOG.md

@ -31,6 +31,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- Fixed the value of the holdings excluded from analysis in the portfolio summary - Fixed the value of the holdings excluded from analysis in the portfolio summary
### Fixed
- Fixed the discovery of the _OpenID Connect_ (`OIDC`) configuration for issuer URLs with a trailing slash (experimental)
## 3.72.0 - 2026-09-20 ## 3.72.0 - 2026-09-20
### Added ### Added

9
apps/api/src/app/auth/auth.module.ts

@ -22,6 +22,7 @@ import { AuthController } from './auth.controller';
import { AuthService } from './auth.service'; import { AuthService } from './auth.service';
import { GoogleStrategy } from './google.strategy'; import { GoogleStrategy } from './google.strategy';
import { JwtStrategy } from './jwt.strategy'; import { JwtStrategy } from './jwt.strategy';
import { getOidcDiscoveryUrl } from './oidc.helper';
import { OidcStrategy } from './oidc.strategy'; import { OidcStrategy } from './oidc.strategy';
@Module({ @Module({
@ -94,9 +95,15 @@ import { OidcStrategy } from './oidc.strategy';
// Fetch OIDC configuration from discovery endpoint // Fetch OIDC configuration from discovery endpoint
try { try {
const response = await fetchService.fetch( const response = await fetchService.fetch(
`${issuer}/.well-known/openid-configuration` getOidcDiscoveryUrl(issuer)
); );
if (!response.ok) {
throw new Error(
`OIDC discovery request failed with status ${response.status}`
);
}
const config = (await response.json()) as { const config = (await response.json()) as {
authorization_endpoint: string; authorization_endpoint: string;
token_endpoint: string; token_endpoint: string;

20
apps/api/src/app/auth/oidc.helper.spec.ts

@ -0,0 +1,20 @@
import { getOidcDiscoveryUrl } from './oidc.helper';
describe('getOidcDiscoveryUrl', () => {
it.each([
[
'https://auth.example.com',
'https://auth.example.com/.well-known/openid-configuration'
],
[
'https://auth.example.com/',
'https://auth.example.com/.well-known/openid-configuration'
],
[
'https://auth.example.com/application/o/ghostfolio/',
'https://auth.example.com/application/o/ghostfolio/.well-known/openid-configuration'
]
])('creates the discovery URL for %s', (issuer, expected) => {
expect(getOidcDiscoveryUrl(issuer)).toBe(expected);
});
});

4
apps/api/src/app/auth/oidc.helper.ts

@ -0,0 +1,4 @@
export function getOidcDiscoveryUrl(issuer: string) {
// Remove trailing slashes
return `${issuer.replace(/\/+$/, '')}/.well-known/openid-configuration`;
}
Loading…
Cancel
Save