Skip to content

Commit

Permalink
[entraid] set all optional claims to avoid weird behavior (#48962)
Browse files Browse the repository at this point in the history
Entra sometimes sends the OptionClaims when retrieving a certain application if only SAML2Token is set, other times it doesn't return them.

This PR fills all id and access token values so entra doesn't fail to send the optional token value.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
  • Loading branch information
tigrato authored Nov 14, 2024
1 parent 88f7bcf commit 92293ff
Show file tree
Hide file tree
Showing 3 changed files with 17 additions and 2 deletions.
12 changes: 12 additions & 0 deletions lib/integrations/azureoidc/provision_sso.go
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,18 @@ func setupSSO(ctx context.Context, graphClient *msgraph.Client, appObjectID stri
*securityGroups = "SecurityGroup"
app.GroupMembershipClaims = securityGroups

claimName := "groups"
optionalClaim := []msgraph.OptionalClaim{
{
Name: &claimName,
},
}
app.OptionalClaims = &msgraph.OptionalClaims{
IDToken: optionalClaim,
SAML2Token: optionalClaim,
AccessToken: optionalClaim,
}

err = graphClient.UpdateApplication(ctx, appObjectID, app)

if err != nil {
Expand Down
2 changes: 2 additions & 0 deletions lib/msgraph/client_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -536,6 +536,8 @@ func TestGetApplication(t *testing.T) {
GroupMembershipClaims: toPtr("SecurityGroup"),
IdentifierURIs: &[]string{"goteleport.com"},
OptionalClaims: &OptionalClaims{
AccessToken: []OptionalClaim{},
IDToken: []OptionalClaim{},
SAML2Token: []OptionalClaim{
{
AdditionalProperties: []string{"sam_account_name"},
Expand Down
5 changes: 3 additions & 2 deletions lib/msgraph/models.go
Original file line number Diff line number Diff line change
Expand Up @@ -109,9 +109,10 @@ type OptionalClaim struct {
}

// OptionalClaims represents optional claims in a token.
// Currently, only SAML2 tokens are supported.
type OptionalClaims struct {
SAML2Token []OptionalClaim `json:"saml2Token,omitempty"`
IDToken []OptionalClaim `json:"idToken,omitempty"`
AccessToken []OptionalClaim `json:"accessToken,omitempty"`
SAML2Token []OptionalClaim `json:"saml2Token,omitempty"`
}

type WebApplication struct {
Expand Down

0 comments on commit 92293ff

Please sign in to comment.