diff --git a/.changeset/light-chicken-search.md b/.changeset/light-chicken-search.md new file mode 100644 index 0000000000..aebb53d753 --- /dev/null +++ b/.changeset/light-chicken-search.md @@ -0,0 +1,5 @@ +--- +'@backstage/plugin-auth-backend-module-oidc-provider': patch +--- + +Increased HTTP request timeout used by OIDC authenticator. diff --git a/plugins/auth-backend-module-oidc-provider/src/authenticator.ts b/plugins/auth-backend-module-oidc-provider/src/authenticator.ts index eddf57a55b..c3754b6f19 100644 --- a/plugins/auth-backend-module-oidc-provider/src/authenticator.ts +++ b/plugins/auth-backend-module-oidc-provider/src/authenticator.ts @@ -15,6 +15,8 @@ */ import { + custom, + CustomHttpOptionsProvider, Issuer, ClientAuthMethod, TokenSet, @@ -30,6 +32,14 @@ import { PassportOAuthPrivateInfo, } from '@backstage/plugin-auth-node'; +const HTTP_OPTION_TIMEOUT = 10000; +const httpOptionsProvider: CustomHttpOptionsProvider = (_url, options) => { + return { + ...options, + timeout: HTTP_OPTION_TIMEOUT, + }; +}; + /** * authentication result for the OIDC which includes the token set and user * profile response @@ -66,7 +76,11 @@ export const oidcAuthenticator = createOAuthAuthenticator({ const initializedScope = config.getOptionalString('scope'); const initializedPrompt = config.getOptionalString('prompt'); + Issuer[custom.http_options] = httpOptionsProvider; const promise = Issuer.discover(metadataUrl).then(issuer => { + issuer[custom.http_options] = httpOptionsProvider; + issuer.Client[custom.http_options] = httpOptionsProvider; + const client = new issuer.Client({ access_type: 'offline', // this option must be passed to provider to receive a refresh token client_id: clientId, @@ -78,6 +92,7 @@ export const oidcAuthenticator = createOAuthAuthenticator({ id_token_signed_response_alg: tokenSignedResponseAlg || 'RS256', scope: initializedScope || '', }); + client[custom.http_options] = httpOptionsProvider; const strategy = new OidcStrategy( {