DependencyTrack / DependencyTrack/dependency-track
Auth through Okta using oidc redirects to login page.
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior
TL:DR oidc button does not appear. when forced I get authenticated receive auth token and get redirected back to /login
I have configured oidc with the below configurations and when the login page loads there is no oidc button.
```
API:
- name: ALPINE_OIDC_ENABLED
value: "true"
- name: ALPINE_OIDC_CLIENT_ID
value: "0oa3c5v0mvAxmae8Z4h7"
- name: ALPINE_OIDC_ISSUER
value: "https://example.okta.com/oauth2/aus3c5o9xtS5eLs6u4h7"
- name: ALPINE_OIDC_USERNAME_CLAIM
value: "preferredusername"
- name: "ALPINE_OIDC_USER_PROVISIONING"
value: "true"
UI:
- name: "OIDC_CLIENT_ID"
value: "0oa3c5v0mvAxmae8Z4h7"
- name: "OIDC_SCOPE"
value: "openid profile email address phone offline_access"
- name: "OIDC_FLOW"
value: ""
- name: "OIDC_LOGIN_BUTTON_TEXT"
value: "OKTA SSO"
```
.well-known/openid-configuration response:
`{"issuer":"https://example.okta.com/oauth2/aus3c5o9xtS5eLs6u4h7","authorization_endpoint":"https://example.okta.com/oauth2/aus3c5o9xtS5eLs6u4h7/v1/authorize","token_endpoint":"https://example.okta.com/oauth2/aus3c5o9xtS5eLs6u4h7/v1/token","userinfo_endpoint":"https://example.okta.com/oauth2/aus3c5o9xtS5eLs6u4h7/v1/userinfo","registration_endpoint":"https://example.okta.com/oauth2/v1/clients","jwks_uri":"https://example.okta.com/oauth2/aus3c5o9xtS5eLs6u4h7/v1/keys","response_types_supported":["code","id_token","code id_token","code token","id_token token","code id_token token"],"response_modes_supported":["query","fragment","form_post","okta_post_message"],"grant_types_supported":["authorization_code","implicit","refresh_token","password","urn:ietf:params:oauth:grant-type:device_code"],"subject_types_supported":["public"],"id_token_signing_alg_values_supported":["RS256"],"scopes_supported":["openid","profile","email","address","phone","offline_access","device_sso"],"token_endpoint_auth_methods_supported":["client_secret_basic","client_secret_post","client_secret_jwt","private_key_jwt","none"],"claims_supported":["iss","ver","sub","aud","iat","exp","jti","auth_time","amr","idp","nonce","name","nickname","preferred_username","given_name","middle_name","family_name","email","email_verified","profile","zoneinfo","locale","address","phone_number","picture","website","gender","birthdate","updated_at","at_hash","c_hash"],"code_challenge_methods_supported":["S256"],"introspection_endpoint":"https://example.okta.com/oauth2/aus3c5o9xtS5eLs6u4h7/v1/introspect","introspection_endpoint_auth_methods_supported":["client_secret_basic","client_secret_post","client_secret_jwt","private_key_jwt","none"],"revocation_endpoint":"https://example.okta.com/oauth2/aus3c5o9xtS5eLs6u4h7/v1/revoke","revocation_endpoint_auth_methods_supported":["client_secret_basic","client_secret_post","client_secret_jwt","private_key_jwt","none"],"end_session_endpoint":"https://example.okta.com/oauth2/aus3c5o9xtS5eLs6u4h7/v1/logout","request_parameter_supported":true,"request_object_signing_alg_values_supported":["HS256","HS384","HS512","RS256","RS384","RS512","ES256","ES384","ES512"],"device_authorization_endpoint":"https://example.okta.com/oauth2/aus3c5o9xtS5eLs6u4h7/v1/device/authorize"}`
We have added our entire cert bundle to cacerts to try and resolve this with no luck.
There was an issue that I had read about HTTP_PROXY not being passed to the oidc library in alpine and we are behind a corporate proxy, but this was supposed to be resolved in 4.7, and we are running 4.7.1 .
I have been able to make the button appear by editing the html in browser and setting "style="display: none;" to "true".
When I use the oidc button, I get:
- redirected to our okta instance
- authenticated via adfs sso
- okta redirects me back to deptrack /static/oidc-callback
- there is a call to /dashboard, but I am returned to the login page instead with the button again missing.
when I check local storage in browser i have recieved an auth token with the below info:
```
oidc.user:https://example.okta.com/oauth2/aus3c5o9xtS5eLs6u4h7:0oa3c5v0mvAxmae8Z4h7:
{"id_token":"eyJraWQiOiI3MUFWb09IaVhONnFNMnlZb3ZMTnlhS1VncmFOc0lfVkxINjVEYmRVVDlZIiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiIwMHUzYzY4N20zSFJnSFQ3ajRoNyIsIm5hbWUiOiJBbmRyZXcgRS4gQmFja2VyIiwiZW1haWwiOiJBbmRyZXcuQmFja2VyQHN0bHMuZnJiLm9yZyIsInZlciI6MSwiaXNzIjoiaHR0cHM6Ly9mcmJhbmtzLXFhLm9rdGEuY29tL29hdXRoMi9hdXMzYzVvOXh0UzVlTHM2dTRoNyIsImF1ZCI6IjBvYTNjNXYwbXZBeG1hZThaNGg3IiwiaWF0IjoxNjc4MjEzMTc3LCJleHAiOjE2NzgyMTY3NzcsImp0aSI6IklELldHQVJiR0JpVERGVDhCek9pUmY2RGJpeDZIZjlaRUZ1VWNRV2hpU2l2MzAiLCJhbXIiOlsicHdkIl0sImlkcCI6IjBvYTE4ZDBuazlEemJRTHJZNGg3IiwicHJlZmVycmVkX3VzZXJuYW1lIjoiQW5kcmV3LkJhY2tlckBzdGxzLmZyYi5vcmciLCJhdXRoX3RpbWUiOjE2NzgyMTMwNzgsImF0X2hhc2giOiJEaDJQeldQNmVFTWltWG55LWtlWlB3IiwiZ3JvdXBzIjpbIkRlcGVuZGVuY3kgVHJhY2sgKFNUTCkgUE9DLUFwcGxpY2F0aW9uIEFzc2lnbm1lbnQiXSwidXNlcmlkIjoiaDFhZWIwMSIsInByZWZlcnJlZHVzZXJuYW1lIjoiaDFhZWIwMSJ9.uccEo-29s9_x0ZLOCSzzqicCuvu3B2P_JIzT_SCyhfggVo0zaMJi8U6Ej5IdSdrU9Sc_JPeZxzn8H2FoJGl8qfskvTIxCeG_0NMH48Tzup9KljSK-mM8ozOUYJHiYwFz190jRYEtk0MLRtPaeh5jmWKT_OMKstYSrCYjfkyG8LvZR7WXm-_PoF_uKQcXv3CU4yfgvTVrIMCHCzK24fNmUZ1zr7W0t7ElSZQqYeH-V-mJ1bqAEroKo4vF0m1tQ8rcTZaWmGnDCnMl5CSlVDAOvlF67Ws8aKuCXC_pr-_9eQF-qtJJfxO0Zr04qfhEoDECAWULsfQ-5Gvehi_7zci3_Q","access_token":"eyJraWQiOiI3MUFWb09IaVhONnFNMnlZb3ZMTnlhS1VncmFOc0lfVkxINjVEYmRVVDlZIiwiYWxnIjoiUlMyNTYifQ.eyJ2ZXIiOjEsImp0aSI6IkFULlExS3hMT0dXRm5pOUxJUEc3akxqQURTYTBhVlh4SXBFcEdWaUpNTkU3elUiLCJpc3MiOiJodHRwczovL2ZyYmFua3MtcWEub2t0YS5jb20vb2F1dGgyL2F1czNjNW85eHRTNWVMczZ1NGg3IiwiYXVkIjoiYXBpOi8vZGVmYXVsdCIsImlhdCI6MTY3ODIxMzE3NywiZXhwIjoxNjc4MjE2Nzc3LCJjaWQiOiIwb2EzYzV2MG12QXhtYWU4WjRoNyIsInVpZCI6IjAwdTNjNjg3bTNIUmdIVDdqNGg3Iiwic2NwIjpbInBob25lIiwicHJvZmlsZSIsImFkZHJlc3MiLCJvcGVuaWQiLCJlbWFpbCJdLCJhdXRoX3RpbWUiOjE2NzgyMTMwNzgsInN1YiI6IkFuZHJldy5CYWNrZXJAc3Rscy5mcmIub3JnIiwibmFtZSI6ImgxYWViMDEiLCJncm91cHMiOlsiRGVwZW5kZW5jeSBUcmFjayAoU1RMKSBQT0MtQXBwbGljYXRpb24gQXNzaWdubWVudCJdLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJoMWFlYjAxIn0.s6XKjTbf0k-aj3reMGEhiwj8Jt5ddowSGJhcyP-ZrqJ-xegdDLcH6okHInVmYtXg6ealjb5RH5kY0VEchWjfd6kHvnPy63pzMkKH9ODaEasGe4HGa4wBuOFF1kJ4Hy6Tve3R5piTAXQhTrIKCGFtTkf93uDzHM59a-WmXX0AhS5yRt60vb4lRKLq1A2vH87u8fTiW9cXZL-jHqKrbb8eLt6vyTkFdWix2ykTtTFsifEAmU8Q_ydY9oBeP2waIoNjFpi-QCxCIS1U45q3hC80FXrMphYIXre4LuYWZ_TZg436xDKWok_cGuS4a5KZ7SWsK1Rvsik0MqeBE8mk1v4J_w","token_type":"Bearer","scope":"phone profile address openid email","profile":{"sub":"00u3c687m3HRgHT7j4h7","name":"User1","email":"user1@example.org","ver":1,"jti":"ID.WGARbGBiTDFT8BzOiRf6Dbix6Hf9ZEFuUcQWhiSiv30","amr":["pwd"],"idp":"0oa18d0nk9DzbQLrY4h7","preferred_username":"user1@example.org","auth_time":1678213078,"groups":["Dependency_Track-Application Assignment"],"userid":"user1","preferredusername":"user1"},"expires_at":1678216777}
```
Frankly, I feel like I have done everything to try and get this to work and I can't seem to find any more information.
If anyone has some insights into what I may be running into I would greatly appreciate it.
### Steps to Reproduce
1. open browser developer tools.
2. locate div for oidc button and change from "none" to "true".
`
3. click oidc button
4. follow routing in "Network" tab in browser developer tools.
5. retrieve token from "Local Storage" of "Application" tab in browser developer tools.
### Expected Behavior
login to oidc user account or create a new oidc user account upon authentication through okta and be redirected to /dashboard
### Dependency-Track Version
4.7.1
### Dependency-Track Distribution
Container Image
### Database Server
PostgreSQL
### Database Server Version
12.8
### Browser
Microsoft Edge
### Checklist
- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported
Contributor guide
Assessment
This issue has not been assessed yet.