Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Intercept OIDC linking / data mapping is not updated

オープン
#292 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
30/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
停滞

調査の方向性

まず、提供された mapper 設定を使用して既存ユーザーの Microsoft OIDC リンクフローを再現し、結果として得られる traits と公開メタデータを期待される値と比較します。mapper が期待される姓と名を保持し、アカウントのリンク時に metadata_public.foo と metadata_public.linked_email の両方を設定すれば完了です。

索引モデルが issue の本文から書いたものです。

説明

bug
Preflight checklist
Describe the bug

For existing users, I want to reject OIDC account linking if the email domain does not match the email in the users traits. So for example, if I have a user like this:

identity:
  traits:
    name: 
        first: "John"
        last: "Doe"
    email: "[email protected]"

I want to reject account linking if the user links with a Microsoft account with email [email protected] (the domain is different). I want to accept if it's [email protected] or [email protected] (domain OK).

Unfortunately, to my knowledge this is not possible at the moment. So one workaround I do now is to update the data mapping to include the email in the claims and put that in the public metadata, and then I can check the emails in retrospect. Something like this: if metadata_public.linked_email != traits.email: handle_bad_link().

So I go to https://console.ory.sh/projects/<project>/social-signin/microsoft and set up this data mapping:

local claims = std.extVar('claims');
{
    identity: {
        metadata_public: {
            linked_email: claims.email,
            foo: "bar"
        },
        traits: {
            email: claims.email,
            name: {
                "first": claims.family_name,
                [if "family_name" in claims then "last" else null]: claims.family_name,
            }            
        },
    },
}
What I expect

I expect when I link an account, the first name and last name will be the same. I also expect metadata_public to contain "foo" field and "linked_email" field.

What I get

I get that the first name and last name are different, and the metadata_public is not set.

Reproducing the bug
  1. set up microsoft linking with a "Common" tenant and the scopes outlined below.
  2. Have an existing account, and link that one
  3. Should have first name and last name same, and some data in public metadata. But it's not there
Relevant log output

No response

Relevant configuration
selfservice:
  methods:
    oidc:
      config:
        base_redirect_uri: [redacted]
        providers:
        - client_id: [redacted]
          client_secret: [redacted]
          id: microsoft
          label: Microsoft
          mapper_url: https://storage.googleapis.com/bac-gcs-production/a2fd16ac5b4671e74fd15ccda28b16e3e094a1f3aa5ba39cbf8880bfae3afef18ff3938df83813b03ffca19728526c11508e7ebf4ba03ff764648448db581c20.jsonnet
          microsoft_tenant: common
          provider: microsoft
          scope:
          - https://graph.microsoft.com/User.Read
          - profile
          - email
          - openid
          subject_source: me
      enabled: true
Version

ory network

On which operating system are you observing this issue?

Ory Network

In which environment are you deploying?

None

Additional Context

No response

主要言語
Shell
スター
96
フォーク
8
PR マージ指標
30日以内にマージされた PR はありません

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

ory/network のほかの issue

ory/network の issue をすべて見る

似ている issue

Shell/Bash の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。