Skip to content

fix: allow any scope containing the pam username - #10

Closed
Idefix2020 wants to merge 1 commit into
authelia:masterfrom
Idefix2020:master
Closed

Idefix2020 wants to merge 1 commit into
authelia:masterfrom
Idefix2020:master

Conversation

@Idefix2020

@Idefix2020 Idefix2020 commented Sep 28, 2026 •

Copy link
Copy Markdown

Previously the scope "authelia.pam" was hardcoded, however due to the way authelia parses the yaml config, it is currently impossible to have a dot character in a scope name. Now any scope will work as long as it has the "authelia.pam.username" claim. This PR is neccessary to use oidc until authelia introduces a feature like authelia/authelia#9714 for scope names.

The docs will also have to be adjusted.

This PR fixes #9

Previously the scope "authelia.pam" was hardcoded, however due to the way authelia parses the yaml config, it is currently impossible to have a dot character in a scope name.
Now any scope will work as long as it has the "authelia.pam.username" claim.
@Idefix2020
Idefix2020 requested a review from a team as a code owner September 28, 2026 09:26
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 9f42e3cf-4e89-4b9e-aa2c-2eeccc3404c7


Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the fix Bug fix for existing behaviour label Sep 28, 2026
@james-d-elliott

james-d-elliott commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

The tests (config, device code test) would disagree with this. It may have been an issue previously however it's not the case today.

Please write a test confirming it on the Authelia side.

@nightah

nightah commented Sep 28, 2026

Copy link
Copy Markdown
Member

I think there's some confusion and conflation between scopes, custom claims and how claims are mapped to scopes in both this PR and #9.

authelia/authelia#11803 was merged in v4.39.20 so any version of Authelia from that point on-wards resolved the issue with dots in scope names.

There does seem to be some misleading information in our docs which has been pointed out in #9 which is definitely worth addressing but all-in-all I think #9 is actually a configuration issue/perhaps an coupled with an older version of Authelia as opposed to an actual bug.

@Idefix2020

Copy link
Copy Markdown
Author

You're right, i was indeed using an outdated version of Authelia (v4.39.16) leading to the behaviour described in #9. This PR may still be useful for allowing the user to choose any scope name they want and allowing backwards compatibility with Authelia vesions <4.39.20, but i also see a point in hardcoding the scope name to avoid confusion.

@nightah

nightah commented Sep 29, 2026

Copy link
Copy Markdown
Member

All of our documentation specifies configuring it this way and the scope is a reserved scope for exactly this purpose.

I'll close this off but definitely will take on some suggestions for improving the documentation and certainly calling out the minimum Authelia version to support deploying the PAM module.

@nightah nightah closed this Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fix Bug fix for existing behaviour

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Device authorization requires a pam.authelia custom scope, which is not possible to define; contradicting documentation on this matter

3 participants