Repository navigation
fix: allow any scope containing the pam username - #10
Idefix2020 wants to merge 1 commit into
Conversation
Previously the scope "authelia.pam" was hardcoded, however due to the way authelia parses the yaml config, it is currently impossible to have a dot character in a scope name. Now any scope will work as long as it has the "authelia.pam.username" claim.
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: Comment |
|
The tests (config, device code test) would disagree with this. It may have been an issue previously however it's not the case today. Please write a test confirming it on the Authelia side. |
|
I think there's some confusion and conflation between scopes, custom claims and how claims are mapped to scopes in both this PR and #9. authelia/authelia#11803 was merged in v4.39.20 so any version of Authelia from that point on-wards resolved the issue with dots in scope names. There does seem to be some misleading information in our docs which has been pointed out in #9 which is definitely worth addressing but all-in-all I think #9 is actually a configuration issue/perhaps an coupled with an older version of Authelia as opposed to an actual bug. |
|
You're right, i was indeed using an outdated version of Authelia (v4.39.16) leading to the behaviour described in #9. This PR may still be useful for allowing the user to choose any scope name they want and allowing backwards compatibility with Authelia vesions <4.39.20, but i also see a point in hardcoding the scope name to avoid confusion. |
|
All of our documentation specifies configuring it this way and the scope is a reserved scope for exactly this purpose. I'll close this off but definitely will take on some suggestions for improving the documentation and certainly calling out the minimum Authelia version to support deploying the PAM module. |
Previously the scope "authelia.pam" was hardcoded, however due to the way authelia parses the yaml config, it is currently impossible to have a dot character in a scope name. Now any scope will work as long as it has the "authelia.pam.username" claim. This PR is neccessary to use oidc until authelia introduces a feature like authelia/authelia#9714 for scope names.
The docs will also have to be adjusted.
This PR fixes #9