Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Intercept OIDC linking / data mapping is not updated

Đang mở
#292 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
30/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Đình trệ
Lĩnh vực
authentication

Hướng nghiên cứu

Bắt đầu bằng cách tái hiện luồng liên kết Microsoft OIDC của người dùng hiện có với cấu hình mapper được cung cấp, rồi so sánh các traits và siêu dữ liệu công khai nhận được với các giá trị mong đợi. Hoàn thành khi mapper giữ nguyên tên và họ mong đợi, đồng thời đặt cả metadata_public.foo và metadata_public.linked_email trong quá trình liên kết tài khoản.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bug
Preflight checklist
Describe the bug

For existing users, I want to reject OIDC account linking if the email domain does not match the email in the users traits. So for example, if I have a user like this:

identity:
  traits:
    name: 
        first: "John"
        last: "Doe"
    email: "[email protected]"

I want to reject account linking if the user links with a Microsoft account with email [email protected] (the domain is different). I want to accept if it's [email protected] or [email protected] (domain OK).

Unfortunately, to my knowledge this is not possible at the moment. So one workaround I do now is to update the data mapping to include the email in the claims and put that in the public metadata, and then I can check the emails in retrospect. Something like this: if metadata_public.linked_email != traits.email: handle_bad_link().

So I go to https://console.ory.sh/projects/<project>/social-signin/microsoft and set up this data mapping:

local claims = std.extVar('claims');
{
    identity: {
        metadata_public: {
            linked_email: claims.email,
            foo: "bar"
        },
        traits: {
            email: claims.email,
            name: {
                "first": claims.family_name,
                [if "family_name" in claims then "last" else null]: claims.family_name,
            }            
        },
    },
}
What I expect

I expect when I link an account, the first name and last name will be the same. I also expect metadata_public to contain "foo" field and "linked_email" field.

What I get

I get that the first name and last name are different, and the metadata_public is not set.

Reproducing the bug
  1. set up microsoft linking with a "Common" tenant and the scopes outlined below.
  2. Have an existing account, and link that one
  3. Should have first name and last name same, and some data in public metadata. But it's not there
Relevant log output

No response

Relevant configuration
selfservice:
  methods:
    oidc:
      config:
        base_redirect_uri: [redacted]
        providers:
        - client_id: [redacted]
          client_secret: [redacted]
          id: microsoft
          label: Microsoft
          mapper_url: https://storage.googleapis.com/bac-gcs-production/a2fd16ac5b4671e74fd15ccda28b16e3e094a1f3aa5ba39cbf8880bfae3afef18ff3938df83813b03ffca19728526c11508e7ebf4ba03ff764648448db581c20.jsonnet
          microsoft_tenant: common
          provider: microsoft
          scope:
          - https://graph.microsoft.com/User.Read
          - profile
          - email
          - openid
          subject_source: me
      enabled: true
Version

ory network

On which operating system are you observing this issue?

Ory Network

In which environment are you deploying?

None

Additional Context

No response

Ngôn ngữ chính
Shell
Star
96
Fork
8
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của ory/network

Tất cả issue của ory/network

Issue tương tự

Thêm issue về Shell/Bash

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.