mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-09 04:30:16 +09:00
Backport #39498 by @SHIVANSHGARG07 The OIDC discovery document at `/.well-known/openid-configuration` advertised `id_token` in `response_types_supported`, but `/login/oauth/authorize` only implements the authorization code flow and rejects any other response_type with `unsupported_response_type`. This mismatch caused OIDC client libraries that rely on discovery to attempt the implicit flow and fail silently. This removes `id_token` from `response_types_supported` so discovery matches actual server behavior, and adds an integration test asserting `response_type=id_token` is rejected consistently. Manually verified: rebuilt Gitea, registered an OAuth2 app, confirmed `/.well-known/openid-configuration` no longer lists `id_token`, and confirmed `/login/oauth/authorize?...&response_type=id_token` still correctly returns `error=unsupported_response_type`. Fixes #39482. <!-- Before submitting: - Target the `main` branch; release branches are for backports only. - Use a Conventional Commits title, e.g. `fix(repo): handle empty branch names`. - Read the contributing guidelines: https://github.com/go-gitea/gitea/blob/main/CONTRIBUTING.md - Documentation changes go to https://gitea.com/gitea/docs Describe your change below and link any issue it fixes. --> Co-authored-by: Shivansh Garg <shivanshgarg587@gmail.com>
This commit is contained in:
@@ -31,7 +31,6 @@ func OIDCWellKnown(ctx *context.Context) {
|
||||
"introspection_endpoint": oidcBaseUrl + "/login/oauth/introspect",
|
||||
"response_types_supported": []string{
|
||||
"code",
|
||||
"id_token",
|
||||
},
|
||||
"id_token_signing_alg_values_supported": []string{
|
||||
oauth2_provider.DefaultSigningKey.SigningMethod().Alg(),
|
||||
|
||||
@@ -108,6 +108,7 @@ func TestOAuth2(t *testing.T) {
|
||||
t.Run("AuthorizeNoClientID", testAuthorizeNoClientID)
|
||||
t.Run("AuthorizeUnregisteredRedirect", testAuthorizeUnregisteredRedirect)
|
||||
t.Run("AuthorizeUnsupportedResponseType", testAuthorizeUnsupportedResponseType)
|
||||
t.Run("AuthorizeUnsupportedResponseTypeIDToken", testAuthorizeUnsupportedResponseTypeIDToken)
|
||||
t.Run("AuthorizeUnsupportedCodeChallengeMethod", testAuthorizeUnsupportedCodeChallengeMethod)
|
||||
t.Run("AuthorizeLoginRedirect", testAuthorizeLoginRedirect)
|
||||
t.Run("AuthorizeShow", testAuthorizeShow)
|
||||
@@ -163,6 +164,16 @@ func testAuthorizeUnsupportedResponseType(t *testing.T) {
|
||||
assert.Equal(t, "Only code response type is supported.", u.Query().Get("error_description"))
|
||||
}
|
||||
|
||||
func testAuthorizeUnsupportedResponseTypeIDToken(t *testing.T) {
|
||||
req := NewRequest(t, "GET", "/login/oauth/authorize?client_id=da7da3ba-9a13-4167-856f-3899de0b0138&redirect_uri=https://example.com&response_type=id_token&state=thestate")
|
||||
ctx := loginUser(t, "user1")
|
||||
resp := ctx.MakeRequest(t, req, http.StatusSeeOther)
|
||||
u, err := resp.Result().Location()
|
||||
assert.NoError(t, err)
|
||||
assert.Equal(t, "unsupported_response_type", u.Query().Get("error"))
|
||||
assert.Equal(t, "Only code response type is supported.", u.Query().Get("error_description"))
|
||||
}
|
||||
|
||||
func testAuthorizeUnsupportedCodeChallengeMethod(t *testing.T) {
|
||||
req := NewRequest(t, "GET", "/login/oauth/authorize?client_id=da7da3ba-9a13-4167-856f-3899de0b0138&redirect_uri=https://example.com&response_type=code&state=thestate&code_challenge_method=UNEXPECTED")
|
||||
ctx := loginUser(t, "user1")
|
||||
|
||||
Reference in New Issue
Block a user