mirror of
https://github.com/netbirdio/dex.git
synced 2026-05-22 18:43:53 -07:00
Fail if OIDC config contains hosted domains (#2937)
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
This commit is contained in:
@@ -35,6 +35,14 @@ type Config struct {
|
||||
|
||||
Scopes []string `json:"scopes"` // defaults to "profile" and "email"
|
||||
|
||||
// HostedDomains was an optional list of whitelisted domains when using the OIDC connector with Google.
|
||||
// Only users from a whitelisted domain were allowed to log in.
|
||||
// Support for this option was removed from the OIDC connector.
|
||||
// Consider switching to the Google connector which supports this option.
|
||||
//
|
||||
// Deprecated: will be removed in future releases.
|
||||
HostedDomains []string `json:"hostedDomains"`
|
||||
|
||||
// Certificates for SSL validation
|
||||
RootCAs []string `json:"rootCAs"`
|
||||
|
||||
@@ -112,6 +120,10 @@ func knownBrokenAuthHeaderProvider(issuerURL string) bool {
|
||||
// Open returns a connector which can be used to login users through an upstream
|
||||
// OpenID Connect provider.
|
||||
func (c *Config) Open(id string, logger log.Logger) (conn connector.Connector, err error) {
|
||||
if len(c.HostedDomains) > 0 {
|
||||
return nil, fmt.Errorf("support for the Hosted domains option had been deprecated and removed, consider switching to the Google connector")
|
||||
}
|
||||
|
||||
httpClient, err := httpclient.NewHTTPClient(c.RootCAs, c.InsecureSkipVerify)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
|
||||
Reference in New Issue
Block a user