add config option to define a OIDC JWKS URL - #1106
Open
SilPan wants to merge 1 commit into
Open
Conversation
This can be usefull if the OIDC configuration discovery fails.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I had lots of trouble getting OIDC running, with my organizations IDP: NetScaler with a weird configuration.
IRIS' OIDC implementation works like the following
source/app/iris_engine/access_control/oidc_handler.py:oidc_handler()tries to get the OIDC config via"OIDC_ISSUER_URL"/.well-known/openid-configuration, if this fails [1] it will consult the configuration values for each of the URLs.This is a perfectly sane and good implementation.
Now because of the weird configuration of our IDP I had to set all the URLs manually.
Going down the exception handling branch - which may be not commonly used.
Doing so I kept being hit with a
jwkest.jws.NoSuitableSigningKeysException.For some reason, the whole flow worked, until IRIS tried to validate that the token came from the actual IDP.
It turned out that IRIS had 0 signing keys it compared with - so of course no key matched.
After lots of debugging I figured out that passing a
jwks_urito theProviderConfigurationResponseinsource/app/iris_engine/access_control/oidc_handler.py:oidc_handler()solved this.Thus I made a PR that introduces this configuration value.
[1] e.g. because my genius sysadmins have the discovery document at
https://access.company.tld/oauth/idp/.well-known/openid-configuration(note the/oauth/idp/path) but the issuer still beinghttps://access.company.tld/instead of respectivehttps://access.company.tld/oauth/idp/.