diff --git a/routers/web/auth/oauth2_wellknown.go b/routers/web/auth/oauth2_wellknown.go index 6fb82b3cbd4..9798a826f91 100644 --- a/routers/web/auth/oauth2_wellknown.go +++ b/routers/web/auth/oauth2_wellknown.go @@ -31,7 +31,6 @@ func OIDCWellKnown(ctx *context.Context) { "introspection_endpoint": oidcBaseUrl + "/login/oauth/introspect", "response_types_supported": []string{ "code", - "id_token", }, "id_token_signing_alg_values_supported": []string{ oauth2_provider.DefaultSigningKey.SigningMethod().Alg(), diff --git a/tests/integration/oauth_test.go b/tests/integration/oauth_test.go index dbf9d7f226b..7ce463b361b 100644 --- a/tests/integration/oauth_test.go +++ b/tests/integration/oauth_test.go @@ -108,6 +108,7 @@ func TestOAuth2(t *testing.T) { t.Run("AuthorizeNoClientID", testAuthorizeNoClientID) t.Run("AuthorizeUnregisteredRedirect", testAuthorizeUnregisteredRedirect) t.Run("AuthorizeUnsupportedResponseType", testAuthorizeUnsupportedResponseType) + t.Run("AuthorizeUnsupportedResponseTypeIDToken", testAuthorizeUnsupportedResponseTypeIDToken) t.Run("AuthorizeUnsupportedCodeChallengeMethod", testAuthorizeUnsupportedCodeChallengeMethod) t.Run("AuthorizeLoginRedirect", testAuthorizeLoginRedirect) t.Run("AuthorizeShow", testAuthorizeShow) @@ -163,6 +164,16 @@ func testAuthorizeUnsupportedResponseType(t *testing.T) { assert.Equal(t, "Only code response type is supported.", u.Query().Get("error_description")) } +func testAuthorizeUnsupportedResponseTypeIDToken(t *testing.T) { + req := NewRequest(t, "GET", "/login/oauth/authorize?client_id=da7da3ba-9a13-4167-856f-3899de0b0138&redirect_uri=https://example.com&response_type=id_token&state=thestate") + ctx := loginUser(t, "user1") + resp := ctx.MakeRequest(t, req, http.StatusSeeOther) + u, err := resp.Result().Location() + assert.NoError(t, err) + assert.Equal(t, "unsupported_response_type", u.Query().Get("error")) + assert.Equal(t, "Only code response type is supported.", u.Query().Get("error_description")) +} + func testAuthorizeUnsupportedCodeChallengeMethod(t *testing.T) { req := NewRequest(t, "GET", "/login/oauth/authorize?client_id=da7da3ba-9a13-4167-856f-3899de0b0138&redirect_uri=https://example.com&response_type=code&state=thestate&code_challenge_method=UNEXPECTED") ctx := loginUser(t, "user1")