Intercept OIDC linking / data mapping is not updated
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 30/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Lĩnh vực
- authentication
Hướng nghiên cứu
Bắt đầu bằng cách tái hiện luồng liên kết Microsoft OIDC của người dùng hiện có với cấu hình mapper được cung cấp, rồi so sánh các traits và siêu dữ liệu công khai nhận được với các giá trị mong đợi. Hoàn thành khi mapper giữ nguyên tên và họ mong đợi, đồng thời đặt cả metadata_public.foo và metadata_public.linked_email trong quá trình liên kết tài khoản.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- This issue affects my Ory Network project.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Describe the bug
For existing users, I want to reject OIDC account linking if the email domain does not match the email in the users traits. So for example, if I have a user like this:
identity:
traits:
name:
first: "John"
last: "Doe"
email: "[email protected]"
I want to reject account linking if the user links with a Microsoft account with email [email protected] (the domain is different). I want to accept if it's [email protected] or [email protected] (domain OK).
Unfortunately, to my knowledge this is not possible at the moment. So one workaround I do now is to update the data mapping to include the email in the claims and put that in the public metadata, and then I can check the emails in retrospect. Something like this: if metadata_public.linked_email != traits.email: handle_bad_link().
So I go to https://console.ory.sh/projects/<project>/social-signin/microsoft and set up this data mapping:
local claims = std.extVar('claims');
{
identity: {
metadata_public: {
linked_email: claims.email,
foo: "bar"
},
traits: {
email: claims.email,
name: {
"first": claims.family_name,
[if "family_name" in claims then "last" else null]: claims.family_name,
}
},
},
}
What I expect
I expect when I link an account, the first name and last name will be the same. I also expect metadata_public to contain "foo" field and "linked_email" field.
What I get
I get that the first name and last name are different, and the metadata_public is not set.
Reproducing the bug
- set up microsoft linking with a "Common" tenant and the scopes outlined below.
- Have an existing account, and link that one
- Should have first name and last name same, and some data in public metadata. But it's not there
Relevant log output
No response
Relevant configuration
selfservice:
methods:
oidc:
config:
base_redirect_uri: [redacted]
providers:
- client_id: [redacted]
client_secret: [redacted]
id: microsoft
label: Microsoft
mapper_url: https://storage.googleapis.com/bac-gcs-production/a2fd16ac5b4671e74fd15ccda28b16e3e094a1f3aa5ba39cbf8880bfae3afef18ff3938df83813b03ffca19728526c11508e7ebf4ba03ff764648448db581c20.jsonnet
microsoft_tenant: common
provider: microsoft
scope:
- https://graph.microsoft.com/User.Read
- profile
- email
- openid
subject_source: me
enabled: true
Version
ory network
On which operating system are you observing this issue?
Ory Network
In which environment are you deploying?
None
Additional Context
No response
- Ngôn ngữ chính
- Shell
- Star
- 96
- Fork
- 8
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của ory/network
-
bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking responseĐang mởbug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
-
Ory Account Experience (hosted UI) registration trait setup via creation of registration flowĐang mởfeat
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
-
selfservice.flows.login.style reverts to identifier_first despite explicitly setting passwordĐang mởbug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 30/100
-
feat
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
Issue tương tự
-
documentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
githubnext/gh-aw-workshop#3969 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Request: Remove l-town appĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
getumbrel/umbrel-apps#6137 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
🎙️ task - fix(deployer): deploy --env prep runs deploy:dev where the repo declares deploy:prepĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
-
backlog bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
WLAN-Pi/wlanpi-profiler#306 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area: backend good first issue priority: P3 - low size: S type: bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Mizithra/ActiveTerrain#31 ·