spring-projects / spring-projects/spring-security
Support for OpenID Connect Session Management session_state parameter
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
It would be great if the retrieval of the session_state request paramter used in OpenID Connect Session Management could be added to OidcAuthorizationCodeAuthenticationProvider.authenticate() method so that the value is added to the AbstractAuthenticationToken.details.
As of today I didn't find any convenient way to retrieve this parameter, except adding a custom AuthenticationSuccessHandler that retrieve this parameter to save it in session during the authentication phase.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at OidcAuthorizationCodeAuthenticationProvider.authenticate() and trace how the session_state request parameter and AbstractAuthenticationToken.details are currently handled. Confirm the expected behavior from the linked OpenID Connect Session Management specification, then verify that the parameter is available through the authentication token details without requiring a custom AuthenticationSuccessHandler.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100