simplesamlphp / simplesamlphp/simplesamlphp-module-oidc

User identifier attribute option as single value is inadequate with heterogenous IdPs scenarios

Offen
#307 1 Kommentar 0 Reaktionen 1 zugewiesene Person Auf GitHub ansehen

@cicnavi arbeitet bereits daran.

Seit 03.6.2025.

enhancement prepared
Vorherrschende Sprache
PHP
Sterne
50
Forks
28
Ø Merge
1 Min.
Gemergte PRs (30 T.)
2

Beschreibung

Config option for designating user identifier https://github.com/simplesamlphp/simplesamlphp-module-oidc/blob/0080cf2ca10a6c00a80835a9e83638245ce9ea82/config/module_oidc.php.dist#L79 is a single value. This means that it is expected that this attribute is always available in the set of user attributes after user authentication.

In scenarios with multiple different IdPs, like for example in eduGAIN inter-federation, not every IdP will be able (or willing) to provide designated identifier. For this reason, this config option (and all relevant code that uses it) should be refactored in a way to be able to accept multiple prioritized values (array of prioritized values), or be left as single value.

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.