Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Intercept OIDC linking / data mapping is not updated

Abierto
#292 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
30/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Estancado

Línea de trabajo

Comienza reproduciendo el flujo de vinculación de Microsoft OIDC para usuarios existentes con la configuración del mapper proporcionada y compara los traits y metadatos públicos resultantes con los valores esperados. Se considera terminado cuando el mapper conserva los nombres y apellidos esperados y establece tanto metadata_public.foo como metadata_public.linked_email durante la vinculación de la cuenta.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

bug
Preflight checklist
Describe the bug

For existing users, I want to reject OIDC account linking if the email domain does not match the email in the users traits. So for example, if I have a user like this:

identity:
  traits:
    name: 
        first: "John"
        last: "Doe"
    email: "[email protected]"

I want to reject account linking if the user links with a Microsoft account with email [email protected] (the domain is different). I want to accept if it's [email protected] or [email protected] (domain OK).

Unfortunately, to my knowledge this is not possible at the moment. So one workaround I do now is to update the data mapping to include the email in the claims and put that in the public metadata, and then I can check the emails in retrospect. Something like this: if metadata_public.linked_email != traits.email: handle_bad_link().

So I go to https://console.ory.sh/projects/<project>/social-signin/microsoft and set up this data mapping:

local claims = std.extVar('claims');
{
    identity: {
        metadata_public: {
            linked_email: claims.email,
            foo: "bar"
        },
        traits: {
            email: claims.email,
            name: {
                "first": claims.family_name,
                [if "family_name" in claims then "last" else null]: claims.family_name,
            }            
        },
    },
}
What I expect

I expect when I link an account, the first name and last name will be the same. I also expect metadata_public to contain "foo" field and "linked_email" field.

What I get

I get that the first name and last name are different, and the metadata_public is not set.

Reproducing the bug
  1. set up microsoft linking with a "Common" tenant and the scopes outlined below.
  2. Have an existing account, and link that one
  3. Should have first name and last name same, and some data in public metadata. But it's not there
Relevant log output

No response

Relevant configuration
selfservice:
  methods:
    oidc:
      config:
        base_redirect_uri: [redacted]
        providers:
        - client_id: [redacted]
          client_secret: [redacted]
          id: microsoft
          label: Microsoft
          mapper_url: https://storage.googleapis.com/bac-gcs-production/a2fd16ac5b4671e74fd15ccda28b16e3e094a1f3aa5ba39cbf8880bfae3afef18ff3938df83813b03ffca19728526c11508e7ebf4ba03ff764648448db581c20.jsonnet
          microsoft_tenant: common
          provider: microsoft
          scope:
          - https://graph.microsoft.com/User.Read
          - profile
          - email
          - openid
          subject_source: me
      enabled: true
Version

ory network

On which operating system are you observing this issue?

Ory Network

In which environment are you deploying?

None

Additional Context

No response

Lenguaje dominante
Shell
Estrellas
96
Forks
8
Métricas de merge de PR
Sin PR fusionados en 30 d

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de ory/network

Todos los issues de ory/network

Issues similares

Más issues de Shell/Bash

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.