Commit 3d587a1
feat(fe): SSO sign-in via two-hop OIDC discovery
II admins can register an organization by `discovery_domain` via
`add_discoverable_oidc_config` (backend, already shipped in dfinity#3778). This
PR adds the matching frontend: a user clicks "Sign in with SSO", types
their organization domain, and the frontend performs a two-hop discovery
chain to resolve the provider's OAuth endpoint before redirecting them
to sign in.
Discovery is lazy and user-initiated — the picker doesn't render one
button per organization, just a single "Sign in with SSO" entry that
leads to the domain input screen.
# Changes
**Type alignment with backend.** The frontend `DiscoverableOidcConfig`
now matches main's Candid type exactly:
`{ discovery_domain: string }`. Everything else (`client_id`, `logo`,
`name`, etc.) is resolved on demand during discovery — the backend
only stores the domain.
**Two-hop discovery (`ssoDiscovery.ts`, new).**
1. `GET https://{domain}/.well-known/ii-openid-configuration` returns
`{ client_id, openid_configuration }`. The domain owner is
responsible for publishing this at their DNS-backed origin.
2. `GET {openid_configuration}` is the provider's standard OIDC
discovery, yielding `authorization_endpoint` and `scopes_supported`.
Both hops run entirely from the browser. (The backend does its own
two-hop discovery via HTTPS outcalls in `src/internet_identity/src/
openid/generic.rs`; keeping the two implementations separate for now
simplifies BE↔FE synchronization.)
**SSO flow UI.**
- `SignInWithSso.svelte` (new): domain input screen. On submit it
validates DNS format, checks the domain is in the backend's
`oidc_configs`, runs `discoverSsoConfig`, then calls
`continueWithSso` to redirect. If the domain isn't registered, shows
"This domain is not registered as an OIDC provider." inline.
- `SsoIcon.svelte` (new): key icon for the SSO button.
- `PickAuthenticationMethod.svelte`: renders the SSO button whenever
`oidc_configs` is non-empty. Does not render per-provider buttons —
users don't know which IdP their org uses, they just type their
domain.
- `authFlow.svelte.ts`: new `signInWithSso` view + `continueWithSso()`
method that synthesizes an `OpenIdConfig` from discovery results and
hands off to the existing `continueWithOpenId` flow.
**Security.**
- Domain input is DNS-format validated (length, label length, no
special characters).
- `oidc_configs` from the backend is the sole allowlist of which
organizations can initiate SSO. No hardcoded domain allowlist in
frontend code.
- All three URLs (the .well-known, the discovery, the auth endpoint)
must be HTTPS.
- The `openid_configuration` URL from hop 1 must be on a trusted OIDC
provider domain (Google, Apple, Microsoft, Okta, login.dfinity.org).
- Issuer hostname in the provider discovery must match the
`openid_configuration` hostname *exactly* or as a true subdomain —
using `endsWith` alone would accept look-alikes like
`evildfinity.okta.com`.
- Authorization endpoint hostname is constrained to the same, not just
HTTPS-validated, so a tampered discovery response can't redirect the
auth step off-host.
- Per-domain rate limit (1 attempt per 10 min), max 2 concurrent
discoveries, 4-hour cache per hop, exponential backoff, timeouts
(5s for hop 1, 10s for hop 2) with `clearTimeout` in `finally` so a
failed fetch can't leak an armed abort timer.
**Cleanup of stale assumptions.**
- Removed the earlier draft's eager per-provider button rendering in
`PickAuthenticationMethod` — those were based on a richer
`DiscoverableOidcConfig` shape that didn't survive into main.
- Removed `authFlow.continueWithOidc` and `openID.findConfig`'s
`oidc_configs` extension for the same reason; they assumed the
config contained a pre-supplied `client_id`, which it no longer
does.
# Tests
- 23 tests in `ssoDiscovery.test.ts`: domain validation,
allowlist-at-caller discipline, two-hop happy path, cache, retry,
trusted-provider check, HTTPS enforcement, issuer/auth-endpoint
hostname exact-match (including an `evildfinity.okta.com`
regression case), off-host auth-endpoint rejection, non-object
responses.
- 22 tests in `openID.test.ts` preserved, including 4 for
`selectAuthScopes` (the shared defaults-fallback helper used by
`continueWithSso`).
- `npm run lint` and `svelte-check` on touched files: clean.
Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]>1 parent e68167f commit 3d587a1
10 files changed
Lines changed: 1060 additions & 13 deletions
File tree
- src/frontend/src/lib
- components
- icons
- wizards/auth
- views
- flows
- utils
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
Lines changed: 31 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| 16 | + | |
| 17 | + | |
16 | 18 | | |
17 | 19 | | |
18 | 20 | | |
| |||
93 | 95 | | |
94 | 96 | | |
95 | 97 | | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
96 | 121 | | |
97 | 122 | | |
98 | 123 | | |
| |||
122 | 147 | | |
123 | 148 | | |
124 | 149 | | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
125 | 155 | | |
126 | 156 | | |
127 | 157 | | |
| |||
149 | 179 | | |
150 | 180 | | |
151 | 181 | | |
| 182 | + | |
152 | 183 | | |
153 | 184 | | |
154 | 185 | | |
| |||
Lines changed: 23 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
| |||
12 | 13 | | |
13 | 14 | | |
14 | 15 | | |
| 16 | + | |
15 | 17 | | |
16 | 18 | | |
17 | | - | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
18 | 24 | | |
19 | 25 | | |
20 | 26 | | |
| |||
33 | 39 | | |
34 | 40 | | |
35 | 41 | | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
36 | 47 | | |
37 | 48 | | |
38 | 49 | | |
| |||
79 | 90 | | |
80 | 91 | | |
81 | 92 | | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
82 | 104 | | |
83 | 105 | | |
84 | 106 | | |
| |||
Lines changed: 138 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
| 36 | + | |
36 | 37 | | |
| 38 | + | |
37 | 39 | | |
38 | 40 | | |
39 | 41 | | |
| |||
47 | 49 | | |
48 | 50 | | |
49 | 51 | | |
| 52 | + | |
50 | 53 | | |
51 | 54 | | |
52 | 55 | | |
| |||
90 | 93 | | |
91 | 94 | | |
92 | 95 | | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
93 | 130 | | |
94 | 131 | | |
95 | 132 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
23 | 29 | | |
24 | 30 | | |
25 | 31 | | |
| |||
29 | 35 | | |
30 | 36 | | |
31 | 37 | | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
| 38 | + | |
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | 44 | | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
45 | 52 | | |
46 | 53 | | |
47 | 54 | | |
| |||
60 | 67 | | |
61 | 68 | | |
62 | 69 | | |
63 | | - | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
64 | 84 | | |
65 | 85 | | |
66 | 86 | | |
| |||
0 commit comments