Commit 2c87bfd
authored
fix: allow OIDC tokens without tenant claim when tenant resolved from subdomain (#1362)
The TenantAuthorizationMiddleware blocked requests with empty JWT tenant
claims even when the tenant was successfully resolved from subdomain or
X-Tenant-Slug header. This prevented standard OIDC providers like Dex
(which issue identity-only tokens without custom tenant claims) from
working with subdomain-based tenant routing.
When JWT has no tenant claim and the user is not a platform admin, now
checks if a tenant was resolved from the request context (subdomain/slug)
and allows the request scoped to that tenant.
Co-authored-by: Ben Coombs <bjcoombs@users.noreply.github.com>1 parent 92856c3 commit 2c87bfd
2 files changed
Lines changed: 56 additions & 8 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
245 | 245 | | |
246 | 246 | | |
247 | 247 | | |
248 | | - | |
249 | | - | |
250 | | - | |
251 | | - | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
252 | 252 | | |
253 | 253 | | |
254 | 254 | | |
| |||
259 | 259 | | |
260 | 260 | | |
261 | 261 | | |
262 | | - | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
263 | 276 | | |
264 | 277 | | |
265 | 278 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
353 | 353 | | |
354 | 354 | | |
355 | 355 | | |
356 | | - | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
| 388 | + | |
357 | 389 | | |
358 | 390 | | |
359 | 391 | | |
| |||
362 | 394 | | |
363 | 395 | | |
364 | 396 | | |
365 | | - | |
366 | | - | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
367 | 402 | | |
368 | 403 | | |
369 | 404 | | |
| |||
0 commit comments