Skip to content

Commit

Permalink
add username to OIDC introspection response (#31688)
Browse files Browse the repository at this point in the history
This field is specified as optional here:
https://datatracker.ietf.org/doc/html/rfc7662#section-2.2

It's used by some OIDC integrations, e.g.
https://emersion.fr/blog/2022/irc-and-oauth2/

Co-authored-by: Giteabot <[email protected]>
  • Loading branch information
slingamn and GiteaBot authored Jul 25, 2024
1 parent bae87df commit ecc8f2b
Show file tree
Hide file tree
Showing 2 changed files with 10 additions and 4 deletions.
8 changes: 6 additions & 2 deletions routers/web/auth/oauth.go
Original file line number Diff line number Diff line change
Expand Up @@ -353,8 +353,9 @@ func IntrospectOAuth(ctx *context.Context) {
}

var response struct {
Active bool `json:"active"`
Scope string `json:"scope,omitempty"`
Active bool `json:"active"`
Scope string `json:"scope,omitempty"`
Username string `json:"username,omitempty"`
jwt.RegisteredClaims
}

Expand All @@ -371,6 +372,9 @@ func IntrospectOAuth(ctx *context.Context) {
response.Audience = []string{app.ClientID}
response.Subject = fmt.Sprint(grant.UserID)
}
if user, err := user_model.GetUserByID(ctx, grant.UserID); err == nil {
response.Username = user.Name
}
}
}

Expand Down
6 changes: 4 additions & 2 deletions tests/integration/oauth_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -450,12 +450,14 @@ func TestOAuthIntrospection(t *testing.T) {
req.Header.Add("Authorization", "Basic ZGE3ZGEzYmEtOWExMy00MTY3LTg1NmYtMzg5OWRlMGIwMTM4OjRNSzhOYTZSNTVzbWRDWTBXdUNDdW1aNmhqUlBuR1k1c2FXVlJISGpKaUE9")
resp = MakeRequest(t, req, http.StatusOK)
type introspectResponse struct {
Active bool `json:"active"`
Scope string `json:"scope,omitempty"`
Active bool `json:"active"`
Scope string `json:"scope,omitempty"`
Username string `json:"username"`
}
introspectParsed := new(introspectResponse)
assert.NoError(t, json.Unmarshal(resp.Body.Bytes(), introspectParsed))
assert.True(t, introspectParsed.Active)
assert.Equal(t, "user1", introspectParsed.Username)

// successful request with a valid client_id/client_secret, but an invalid token
req = NewRequestWithValues(t, "POST", "/login/oauth/introspect", map[string]string{
Expand Down

0 comments on commit ecc8f2b

Please sign in to comment.