Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Motivation
In testing 2.1.1, I found that the forwarding did not work correctly when using
auth_mode: openidconnect
. Specifically, loading the main page would result in loading keycloak. These changes improve theopenidconnect
auth mode and ensure that the other auth modes still work.Changes
oauth2
configuration. Since we haven't actually released any of these configurations, I am changing them now.openid
scope to the browser's request, since it is expected by some providers, like Okta./api/v1/auth/token
endpoints.Verifying the change
I verified these changes with all 4 auth modes an EKS cluster and against the DataStax Pulsar Helm Chart.