Browse Source

Merge 5d72ed2674 into 0cefa4cca7

pull/7566/merge
kittygaming99 7 days ago
committed by GitHub
parent
commit
9b3b2c7fcc
No known key found for this signature in database GPG Key ID: B5690EEEBB952194
  1. 2
      src/config.rs
  2. 14
      src/sso.rs

2
src/config.rs

@ -831,6 +831,8 @@ make_config! {
sso_scopes: String, true, def, "email profile".to_owned(); sso_scopes: String, true, def, "email profile".to_owned();
/// Authorization request extra parameters /// Authorization request extra parameters
sso_authorize_extra_params: String, true, def, String::new(); sso_authorize_extra_params: String, true, def, String::new();
/// SSO name claim |> The OIDC claim to use for the user's display name. Falls back to `preferred_username`.
sso_name_claim: String, true, def, "name".to_string();
/// Use PKCE during Authorization flow /// Use PKCE during Authorization flow
sso_pkce: bool, true, def, true; sso_pkce: bool, true, def, true;
/// Regex for additional trusted Id token audience |> By default only the client_id is trusted. /// Regex for additional trusted Id token audience |> By default only the client_id is trusted.

14
src/sso.rs

@ -288,7 +288,19 @@ pub async fn exchange_code(
let email_verified = id_claims.email_verified().or(user_info.email_verified()); let email_verified = id_claims.email_verified().or(user_info.email_verified());
let user_name = id_claims.preferred_username().or(user_info.preferred_username()).map(|un| un.to_string()); let configured_claim = CONFIG.sso_name_claim();
let extract_claim = |claims: &serde_json::Value, claim_key: &str| -> Option<String> {
claims.get(claim_key).and_then(|v| v.as_str()).map(|s| s.to_string())
};
let id_claims_json = serde_json::to_value(&id_claims).unwrap_or_default();
let user_info_json = serde_json::to_value(&user_info).unwrap_or_default();
let user_name = extract_claim(&id_claims_json, &configured_claim)
.or_else(|| extract_claim(&user_info_json, &configured_claim))
.or_else(|| id_claims.preferred_username().map(|n| n.to_string()))
.or_else(|| user_info.preferred_username().map(|n| n.to_string()));
let refresh_token = token_response.refresh_token().map(openidconnect::RefreshToken::secret); let refresh_token = token_response.refresh_token().map(openidconnect::RefreshToken::secret);
if refresh_token.is_none() && CONFIG.sso_scopes_vec().contains(&"offline_access".to_owned()) { if refresh_token.is_none() && CONFIG.sso_scopes_vec().contains(&"offline_access".to_owned()) {

Loading…
Cancel
Save