Intercept OIDC linking / data mapping is not updated
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 30/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Estancado
- Área
- authentication
Línea de trabajo
Comienza reproduciendo el flujo de vinculación de Microsoft OIDC para usuarios existentes con la configuración del mapper proporcionada y compara los traits y metadatos públicos resultantes con los valores esperados. Se considera terminado cuando el mapper conserva los nombres y apellidos esperados y establece tanto metadata_public.foo como metadata_public.linked_email durante la vinculación de la cuenta.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- This issue affects my Ory Network project.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Describe the bug
For existing users, I want to reject OIDC account linking if the email domain does not match the email in the users traits. So for example, if I have a user like this:
identity:
traits:
name:
first: "John"
last: "Doe"
email: "[email protected]"
I want to reject account linking if the user links with a Microsoft account with email [email protected] (the domain is different). I want to accept if it's [email protected] or [email protected] (domain OK).
Unfortunately, to my knowledge this is not possible at the moment. So one workaround I do now is to update the data mapping to include the email in the claims and put that in the public metadata, and then I can check the emails in retrospect. Something like this: if metadata_public.linked_email != traits.email: handle_bad_link().
So I go to https://console.ory.sh/projects/<project>/social-signin/microsoft and set up this data mapping:
local claims = std.extVar('claims');
{
identity: {
metadata_public: {
linked_email: claims.email,
foo: "bar"
},
traits: {
email: claims.email,
name: {
"first": claims.family_name,
[if "family_name" in claims then "last" else null]: claims.family_name,
}
},
},
}
What I expect
I expect when I link an account, the first name and last name will be the same. I also expect metadata_public to contain "foo" field and "linked_email" field.
What I get
I get that the first name and last name are different, and the metadata_public is not set.
Reproducing the bug
- set up microsoft linking with a "Common" tenant and the scopes outlined below.
- Have an existing account, and link that one
- Should have first name and last name same, and some data in public metadata. But it's not there
Relevant log output
No response
Relevant configuration
selfservice:
methods:
oidc:
config:
base_redirect_uri: [redacted]
providers:
- client_id: [redacted]
client_secret: [redacted]
id: microsoft
label: Microsoft
mapper_url: https://storage.googleapis.com/bac-gcs-production/a2fd16ac5b4671e74fd15ccda28b16e3e094a1f3aa5ba39cbf8880bfae3afef18ff3938df83813b03ffca19728526c11508e7ebf4ba03ff764648448db581c20.jsonnet
microsoft_tenant: common
provider: microsoft
scope:
- https://graph.microsoft.com/User.Read
- profile
- email
- openid
subject_source: me
enabled: true
Version
ory network
On which operating system are you observing this issue?
Ory Network
In which environment are you deploying?
None
Additional Context
No response
- Lenguaje dominante
- Shell
- Estrellas
- 96
- Forks
- 8
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ory/network
-
bug
Dificultad 4/5 3-5 días Aptitud para principiantes 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking responseAbiertobug
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
-
Ory Account Experience (hosted UI) registration trait setup via creation of registration flowAbiertofeat
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
-
selfservice.flows.login.style reverts to identifier_first despite explicitly setting passwordAbiertobug
Dificultad 4/5 3-5 días Aptitud para principiantes 30/100
-
feat
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
Todos los issues de ory/network
Issues similares
-
bug good first issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
petry-projects/.github-private#1981 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Update vtm to 2026.9.28Abiertopackage-update
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
oSoWoSo/vOid_Community_repOsitory#207 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
alunduil/alunduil-chezmoi#815 ·
Los mantenedores suelen responder en 1 día
-
good first issue new package
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
wimpysworld/deb-get#2035 ·
Los mantenedores suelen responder en 1 día
-
automation documentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día