fix(auth): allow OIDC token exchange without client_secret - #7049
Open
claxman wants to merge 2 commits into
Open
fix(auth): allow OIDC token exchange without client_secret#7049claxman wants to merge 2 commits into
claxman wants to merge 2 commits into
Conversation
Public clients such as Azure AD B2C reject a client_secret on the token request. Session creation and AuthHandler required one. Fixes google#2256
_is_exchangeable still required client_secret, so parse_and_store and get_auth_response never called the exchanger after login. Fixes google#2256
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Please ensure you have read the contribution guide before creating a pull request.
Link to Issue or Description of Change
1. Link to an existing issue (if applicable):
Problem:
create_oauth2_sessionwithOAuth2Auth(client_id='public-client')returns(None, None).AuthHandler.generate_auth_requestraisesValueError: Auth Scheme SecuritySchemeType.oauth2 requires both client_id and client_secret in auth_credential.oauth2. The issue reports Azure AD B2C public clients reject a secret.Solution:
Require
client_idonly increate_oauth2_session,AuthHandler.generate_auth_request,AuthHandler._is_exchangeable, and the OpenAPIToolAuthHandler. Whenclient_secretis unset and the method is the defaultclient_secret_basic, passnoneintoOAuth2Session.OAuth2Auth.token_endpoint_auth_methodis unchanged; the session getsnonewhen the secret is missing so users do not need a new Literal value.openid_dict_to_scheme_credentialis unchanged; it is not on the issue path.Testing Plan
Unit Tests:
Before the change, the same
create_oauth2_sessionandgenerate_auth_requestcalls onmainreturned(None, None)and raised theValueErrorquoted above.Manual End-to-End (E2E) Tests:
Not run. No Azure AD B2C tenant available, so AADB2C90084 was not reproduced.
Checklist