Merge pull request #4476 from rmanny/remove-default-scope-oidc

Don't pass default as a scope to OIDC providers
This commit is contained in:
Patrik Oldsberg
2021-02-10 22:26:51 +01:00
committed by GitHub
2 changed files with 36 additions and 1 deletions
+35
View File
@@ -0,0 +1,35 @@
---
'@backstage/plugin-auth-backend': minor
---
Remove undocumented scope (default) from the OIDC auth provider which was breaking some identity services. If your app relied on this scope, you can manually specify it by adding a new factory in `packages/app/src/apis.ts`:
```
export const apis = [
createApiFactory({
api: oidcAuthApiRef,
deps: {
discoveryApi: discoveryApiRef,
oauthRequestApi: oauthRequestApiRef,
configApi: configApiRef,
},
factory: ({ discoveryApi, oauthRequestApi, configApi }) =>
OAuth2.create({
discoveryApi,
oauthRequestApi,
provider: {
id: 'oidc',
title: 'Your Identity Provider',
icon: OAuth2Icon,
},
defaultScopes: [
'default',
'openid',
'email',
'offline_access',
],
environment: configApi.getOptionalString('auth.environment'),
}),
}),
];
```
@@ -65,7 +65,7 @@ export class OidcAuthProvider implements OAuthHandlers {
return await executeRedirectStrategy(req, strategy, {
accessType: 'offline',
prompt: 'none',
scope: `${req.scope} default`,
scope: req.scope,
state: encodeState(req.state),
});
}