diff --git a/.changeset/clean-apples-breathe.md b/.changeset/clean-apples-breathe.md index f946b9496a..f3340bf8cd 100644 --- a/.changeset/clean-apples-breathe.md +++ b/.changeset/clean-apples-breathe.md @@ -3,4 +3,4 @@ --- Fixes potential bug introduced in `0.4.10` which causes `OAuth2AuthProvider` to authenticate using credentials in both POST payload and headers. -This might break some stricter OAuth2 implementations so there is now a `basicAuth` config option that can manually be set to `true` to enable this behavior. +This might break some stricter OAuth2 implementations so there is now a `includeBasicAuth` config option that can manually be set to `true` to enable this behavior. diff --git a/plugins/auth-backend/src/providers/oauth2/provider.ts b/plugins/auth-backend/src/providers/oauth2/provider.ts index b7978bcf79..2f9c739860 100644 --- a/plugins/auth-backend/src/providers/oauth2/provider.ts +++ b/plugins/auth-backend/src/providers/oauth2/provider.ts @@ -59,7 +59,7 @@ export type OAuth2AuthProviderOptions = OAuthProviderOptions & { tokenUrl: string; scope?: string; logger: Logger; - basicAuth?: boolean; + includeBasicAuth?: boolean; }; export class OAuth2AuthProvider implements OAuthHandlers { @@ -86,7 +86,7 @@ export class OAuth2AuthProvider implements OAuthHandlers { tokenURL: options.tokenUrl, passReqToCallback: false as true, scope: options.scope, - customHeaders: options.basicAuth + customHeaders: options.includeBasicAuth ? { Authorization: `Basic ${this.encodeClientCredentials( options.clientId, @@ -247,7 +247,7 @@ export const createOAuth2Provider = ( const authorizationUrl = envConfig.getString('authorizationUrl'); const tokenUrl = envConfig.getString('tokenUrl'); const scope = envConfig.getOptionalString('scope'); - const basicAuth = envConfig.getOptionalBoolean('basicAuth'); + const includeBasicAuth = envConfig.getOptionalBoolean('includeBasicAuth'); const disableRefresh = envConfig.getOptionalBoolean('disableRefresh') ?? false; @@ -284,7 +284,7 @@ export const createOAuth2Provider = ( tokenUrl, scope, logger, - basicAuth, + includeBasicAuth, }); return OAuthAdapter.fromConfig(globalConfig, provider, {