spring-projects / spring-projects/spring-security

Support for OpenID Connect Session Management session_state parameter

Open
#14,812 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: oauth2 type: enhancement
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

It would be great if the retrieval of the session_state request paramter used in OpenID Connect Session Management could be added to OidcAuthorizationCodeAuthenticationProvider.authenticate() method so that the value is added to the AbstractAuthenticationToken.details.

As of today I didn't find any convenient way to retrieve this parameter, except adding a custom AuthenticationSuccessHandler that retrieve this parameter to save it in session during the authentication phase.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at OidcAuthorizationCodeAuthenticationProvider.authenticate() and trace how the session_state request parameter and AbstractAuthenticationToken.details are currently handled. Confirm the expected behavior from the linked OpenID Connect Session Management specification, then verify that the parameter is available through the authentication token details without requiring a custom AuthenticationSuccessHandler.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
authentication, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.