Auth: Fix AzureAD public client configuration (#99019)
Auth: Add client auth none as default to ensure public clients can be configured on the UI
This commit is contained in:
@@ -199,7 +199,7 @@ func (s *SocialAzureAD) Exchange(ctx context.Context, code string, authOptions .
|
||||
case social.ClientSecretPost:
|
||||
// Default behavior for ClientSecretPost, no additional setup needed
|
||||
default:
|
||||
s.log.Debug("ClientAuthentication is not set. Using default client authentication method")
|
||||
s.log.Debug("ClientAuthentication is not set. Using default client authentication method: none")
|
||||
}
|
||||
|
||||
// Default token exchange
|
||||
@@ -379,6 +379,9 @@ func validateClientAuthentication(info *social.OAuthInfo, requester identity.Req
|
||||
}
|
||||
return nil
|
||||
|
||||
case social.None:
|
||||
return nil
|
||||
|
||||
default:
|
||||
return ssosettings.ErrInvalidOAuthConfig("Invalid client authentication method.")
|
||||
}
|
||||
|
||||
@@ -16,6 +16,7 @@ const (
|
||||
|
||||
// Values for ClientAuthentication under OAuthInfo (based on oidc spec)
|
||||
ClientSecretPost = "client_secret_post"
|
||||
None = "none"
|
||||
// Azure AD
|
||||
ManagedIdentity = "managed_identity"
|
||||
// Other providers...
|
||||
|
||||
Reference in New Issue
Block a user