IDForwarding: Set identity type and uid (#91830)

* Set identity type and uid

* Set uid without prefix

* Update authlib version

* Update to new claim name
This commit is contained in:
Karl Persson
2024-08-14 10:51:44 +02:00
committed by GitHub
parent d1b0e70f8d
commit 8d36111420
9 changed files with 27 additions and 35 deletions
+3 -2
View File
@@ -96,7 +96,9 @@ func (s *Service) SignIdentity(ctx context.Context, id identity.Requester) (stri
IssuedAt: jwt.NewNumericDate(now),
},
Rest: authnlib.IDTokenClaims{
Namespace: s.nsMapper(id.GetOrgID()),
Namespace: s.nsMapper(id.GetOrgID()),
Identifier: id.GetRawIdentifier(),
Type: id.GetIdentityType(),
},
}
@@ -105,7 +107,6 @@ func (s *Service) SignIdentity(ctx context.Context, id identity.Requester) (stri
claims.Rest.EmailVerified = id.IsEmailVerified()
claims.Rest.AuthenticatedBy = id.GetAuthenticatedBy()
claims.Rest.Username = id.GetLogin()
claims.Rest.UID = id.GetUID()
claims.Rest.DisplayName = id.GetDisplayName()
}
+8 -6
View File
@@ -93,11 +93,12 @@ func TestService_SignIdentity(t *testing.T) {
parsed, err := jwt.ParseSigned(token)
require.NoError(t, err)
claims := &auth.IDClaims{}
require.NoError(t, parsed.UnsafeClaimsWithoutVerification(&claims.Claims, &claims.Rest))
assert.Equal(t, login.AzureADAuthModule, claims.Rest.AuthenticatedBy)
assert.Equal(t, "U1", claims.Rest.Username)
assert.Equal(t, "user:edpu3nnt61se8e", claims.Rest.UID)
gotClaims := &auth.IDClaims{}
require.NoError(t, parsed.UnsafeClaimsWithoutVerification(&gotClaims.Claims, &gotClaims.Rest))
assert.Equal(t, login.AzureADAuthModule, gotClaims.Rest.AuthenticatedBy)
assert.Equal(t, "U1", gotClaims.Rest.Username)
assert.Equal(t, claims.TypeUser, gotClaims.Rest.Type)
assert.Equal(t, "edpu3nnt61se8e", gotClaims.Rest.Identifier)
})
t.Run("should sign identity with authenticated by if user is externally authenticated", func(t *testing.T) {
@@ -117,6 +118,7 @@ func TestService_SignIdentity(t *testing.T) {
assert.Equal(t, login.AzureADAuthModule, gotClaims.Rest.AuthenticatedBy)
assert.Equal(t, "U1", gotClaims.Rest.Username)
assert.Equal(t, "user:edpu3nnt61se8e", gotClaims.Rest.UID)
assert.Equal(t, claims.TypeUser, gotClaims.Rest.Type)
assert.Equal(t, "edpu3nnt61se8e", gotClaims.Rest.Identifier)
})
}