hashicorp / hashicorp/vault-plugin-auth-jwt

Feature Request: Add access_token as an Optional Parameter to /auth/jwt/login for Group Fetching

Open
#264 3 comments 2 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
107
Forks
73
Avg merge
13h 49m
Merged PRs (30d)
7

Description

### Description
I propose adding an `access_token` as an optional parameter to the `/auth/jwt/login` endpoint repository. This feature aims to enable Vault to use the provided access token to fetch a user's groups from Azure AD, specifically in cases where users are members of more than 200 groups.

### Context
Currently, when using the JWT login method with Azure AD, users who are part of a large number of groups encounter limitations. The JWT login method supports only the ID token parameter and lacks the functionality to fetch groups using its own client ID and secret. This limitation becomes evident in scenarios where users are members of more than 200 groups, as the ID token includes claims indicating the groups are available via a separate endpoint.

### Proposed Solution
- Introduce an optional `access_token` parameter in the `/auth/jwt/login` endpoint.
- This access token would be used by Vault to retrieve the user's group membership information from Azure AD.

### Security Considerations
- The implementation will ensure secure handling and storage of the access token to prevent unintended exposure.
- The feature will be designed to align with OAuth 2.0 and OpenID Connect best practices and standards.

### Contribution
N/A

### Request for Feedback
I would greatly appreciate any insights, concerns, or suggestions regarding this proposed feature, especially concerning security implications and best practices in the context of Vault and OAuth 2.0/OIDC standards.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.