Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions internal/server/authn/method/oidc/server.go
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,9 @@ const (
storageMetadataOIDCPicture = "io.flipt.auth.oidc.picture"
storageMetadataOIDCSub = "io.flipt.auth.oidc.sub"
storageMetadataOIDCPreferredUsername = "io.flipt.auth.oidc.preferred_username"
storageMetadataOIDCIssuer = "io.flipt.auth.oidc.issuer"
storageMetadataOIDCClientID = "io.flipt.auth.oidc.client_id"
storageMetadataOIDCIDToken = "io.flipt.auth.oidc.id_token"
oauthChallengeTTL = 2 * time.Minute
nonceStatic = "static"
)
Expand Down Expand Up @@ -174,6 +177,9 @@ func (s *Server) Callback(ctx context.Context, req *auth.CallbackRequest) (_ *au

metadata := map[string]string{
storageMetadataOIDCProvider: req.Provider,
storageMetadataOIDCIssuer: providerCfg.IssuerURL,
storageMetadataOIDCClientID: providerCfg.ClientID,
storageMetadataOIDCIDToken: string(responseToken.IDToken()),
}

rawClaims := make(map[string]any)
Expand Down
8 changes: 7 additions & 1 deletion internal/server/authn/method/oidc/server_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -549,16 +549,22 @@ func testOIDCFlow(t *testing.T, ctx context.Context, tpAddr, clientAddress strin
claims := response.Authentication.Metadata["io.flipt.auth.claims"]
delete(response.Authentication.Metadata, "io.flipt.auth.claims")

idToken := response.Authentication.Metadata["io.flipt.auth.oidc.id_token"]
delete(response.Authentication.Metadata, "io.flipt.auth.oidc.id_token")

assert.Equal(t, map[string]string{
"io.flipt.auth.oidc.provider": "google",
"io.flipt.auth.oidc.email": "mark@flipt.io",
"io.flipt.auth.oidc.issuer": tpAddr,
"io.flipt.auth.oidc.client_id": "client_id",
"io.flipt.auth.oidc.email": "mark@flipt.io",
"io.flipt.auth.email": "mark@flipt.io",
"io.flipt.auth.oidc.name": "Mark Phelps",
"io.flipt.auth.name": "Mark Phelps",
"io.flipt.auth.oidc.sub": "mark",
}, response.Authentication.Metadata)

assert.NotEmpty(t, claims)
assert.NotEmpty(t, idToken)
if expectedUserInfoClaims != nil {
var claimSet map[string]any
require.NoError(t, json.Unmarshal([]byte(claims), &claimSet))
Expand Down
16 changes: 15 additions & 1 deletion ui/src/components/NavUser.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,21 @@ export function NavUser({ user }: { user: User }) {
await expireAuthSelf();
clearSession();
if (user?.issuer) {
window.location.href = `//${user.issuer}`;
const logoutUrl = new URL(
'protocol/openid-connect/logout',
user.issuer.endsWith('/') ? user.issuer : user.issuer + '/'
);
if (user?.idToken) {
logoutUrl.searchParams.set('id_token_hint', user.idToken);
}
if (user?.clientId) {
logoutUrl.searchParams.set('client_id', user.clientId);
}
logoutUrl.searchParams.set(
'post_logout_redirect_uri',
window.location.origin
);
window.location.href = logoutUrl.toString();
} else {
navigate('/login');
}
Expand Down
8 changes: 8 additions & 0 deletions ui/src/data/user.ts
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,14 @@ export function getUser(session?: Session): User | undefined {
if (metadata[authMethodIssuerKey as keyof typeof metadata]) {
u.issuer = metadata[authMethodIssuerKey as keyof typeof metadata];
}
const authMethodClientIdKey = `io.flipt.auth.${authMethod}.client_id`;
if (metadata[authMethodClientIdKey as keyof typeof metadata]) {
u.clientId = metadata[authMethodClientIdKey as keyof typeof metadata];
}
const authMethodIdTokenKey = `io.flipt.auth.${authMethod}.id_token`;
if (metadata[authMethodIdTokenKey as keyof typeof metadata]) {
u.idToken = metadata[authMethodIdTokenKey as keyof typeof metadata];
}
}
return u;
}
Expand Down
3 changes: 3 additions & 0 deletions ui/src/types/auth/OIDC.ts
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@ export interface IAuthMethodOIDC extends IAuthMethod {

export interface IAuthMethodOIDCMetadata {
'io.flipt.auth.oidc.provider': string;
'io.flipt.auth.oidc.issuer'?: string;
'io.flipt.auth.oidc.client_id'?: string;
'io.flipt.auth.oidc.id_token'?: string;
'io.flipt.auth.oidc.email'?: string;
'io.flipt.auth.oidc.email_verified'?: string;
'io.flipt.auth.oidc.name'?: string;
Expand Down
2 changes: 2 additions & 0 deletions ui/src/types/auth/User.ts
Original file line number Diff line number Diff line change
Expand Up @@ -3,5 +3,7 @@ export type User = {
login: string | undefined;
imgURL: string | undefined;
issuer: string | undefined;
clientId: string | undefined;
idToken: string | undefined;
authMethod: string | undefined;
};
Loading