Commit 3b393aa
committed
fix(api): default OIDC discovery issuer to API_EXTERNAL_URL
The /.well-known/openid-configuration handler used config.JWT.Issuer
unconditionally, returning an empty issuer and relative endpoint URLs
for self-hosted operators who configure API_EXTERNAL_URL but leave
GOTRUE_JWT_ISSUER unset. That violates OpenID Connect Discovery 1.0
section 4.2 (issuer MUST be present) and RFC 8414 section 3 (endpoint
URLs MUST be absolute).
Default issuer to config.API.ExternalURL when JWT.Issuer is empty;
API.ExternalURL is required:"true" in the config struct so it is
always populated. Also use the trailing-slash-stripped local variable
when returning the Issuer field so it matches how endpoint URLs are
constructed.
Adds in-process tests asserting that issuer and endpoint URLs are
absolute when JWT.Issuer is empty, and that a trailing slash on a
configured JWT.Issuer is stripped consistently from the issuer field.
Fixes #2487
Signed-off-by: Manas Srivastava <mastermanas805@gmail.com>1 parent 7f88985 commit 3b393aa
2 files changed
Lines changed: 49 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
69 | 72 | | |
70 | 73 | | |
71 | 74 | | |
72 | 75 | | |
73 | 76 | | |
74 | 77 | | |
75 | 78 | | |
76 | | - | |
| 79 | + | |
77 | 80 | | |
78 | 81 | | |
79 | 82 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
9 | 10 | | |
10 | 11 | | |
11 | 12 | | |
| |||
77 | 78 | | |
78 | 79 | | |
79 | 80 | | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
0 commit comments