* Enable passkeys configuration does not follow best UX
Closes#48445
Signed-off-by: Martin Bartoš <mabartos@redhat.com>
* Apply suggestions from the review
Signed-off-by: Martin Bartoš <mabartos@redhat.com>
* Apply suggestion from review
Signed-off-by: Martin Bartoš <mabartos@redhat.com>
---------
Signed-off-by: Martin Bartoš <mabartos@redhat.com>
Fix#44013
The Twitter broker relies on the unmaintained twitter4j library (no release in several years) and Twitter's legacy OAuth 1.0a endpoints. twitter4j uses Java serialization to record its state, which recurs as noise in security reviews.
This deprecates the broker behind a disabled-by-default feature (twitter-broker), mirroring the Instagram broker deprecation. As Twitter(X) now supports OAuth 2.0, the generic OAuth v2 identity provider can be used as a replacement, and the admin guide documents the migration.
Signed-off-by: Bapuji Koraganti <bapuk.2008@gmail.com>
Signed-off-by: Bapuji Koraganti <34816445+bkoragan@users.noreply.github.com>
Signed-off-by: Alexander Schwartz <alexander.schwartz@gmx.net>
Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Alexander Schwartz <alexander.schwartz@gmx.net>
Co-authored-by: Alexander Schwartz <alexander.schwartz@ibm.com>
* Documentation for token scopes
Closes#49607
Signed-off-by: Martin Bartoš <mabartos@redhat.com>
* Update docs/documentation/server_admin/topics/clients/con-parameterized-client-scopes.adoc
Co-authored-by: Ricardo Martin <rmartinc@redhat.com>
Signed-off-by: Martin Bartoš <mabartos@redhat.com>
---------
Signed-off-by: Martin Bartoš <mabartos@redhat.com>
Co-authored-by: Ricardo Martin <rmartinc@redhat.com>
- access to /ServiceProviderConfig, /ResourceTYpes and /Schemas now require only query-users or query-groups.
Closes#47820
Signed-off-by: Stefan Guilhen <sguilhen@redhat.com>
* Initial draft to check CA subject DN in X.509 client authenticator
Closes#48412
Signed-off-by: rmartinc <rmartinc@redhat.com>
* Add the test to the FIPS suites and doc changes
Closes#48412
Signed-off-by: rmartinc <rmartinc@redhat.com>
* Delete AbstractMutualTLSClientTest to move the old test
Closes#48412
Signed-off-by: rmartinc <rmartinc@redhat.com>
* Move the old test to the new test suite
Closes#48412
Signed-off-by: rmartinc <rmartinc@redhat.com>
* final test changes
Closes#48412
Signed-off-by: rmartinc <rmartinc@redhat.com>
* First round of review changes.
Closes#48412
Signed-off-by: rmartinc <rmartinc@redhat.com>
* Add a client executor to add default CA subject DN to client registration
Closes#48412
Signed-off-by: rmartinc <rmartinc@redhat.com>
---------
Signed-off-by: rmartinc <rmartinc@redhat.com>
Closes#49140
The revoke-role step expects multivalued role names, not a
comma-separated string.
Signed-off-by: Thomas DELORGE <thomas.delorge@orbeet.io>
* Make OrganizationGroupMembershipMapper claim name configurable
The OrganizationGroupMembershipMapper introduced in 26.6.0 hardcoded
the token claim name to "organization", unlike OrganizationMembershipMapper
which already exposes the claim name as a configurable property.
- Add TOKEN_CLAIM_NAME config property to OrganizationGroupMembershipMapper
via OIDCAttributeMapperHelper.addTokenClaimNameConfig()
- Override getEffectiveModel() to default the claim name to
OAuth2Constants.ORGANIZATION when not set, preserving backward
compatibility for existing mapper configurations
- Set TOKEN_CLAIM_NAME default in the static create() factory method
- Refactor OIDCAttributeMapperHelper.getOrInitializeOrganizationClaimAsMap()
to accept a ProtocolMapperModel instead of a raw String, delegating
to mapClaim() for correct claim placement (including nested path support)
Closes#47851
Signed-off-by: Sven-Torben Janus <sven-torben.janus@conciso.de>
* Fix nested claim path read and add custom claim name tests
The read side of getOrInitializeOrganizationClaimAsMap was doing a flat
Map.get() on the dotted claim name, while the write side (mapClaim) already
creates a nested structure by splitting on dots. This caused the group mapper
to find nothing when the claim name contained a dot, overwriting the
membership data written by OrganizationMembershipMapper.
Fix by splitting the claim path via splitClaimPath() and traversing the
nested map with a new private getNestedClaimValue() helper in
OIDCAttributeMapperHelper. The helper belongs there rather than in JsonUtils
because it operates on Map<String,Object>, not JsonNode.
Also add integration tests covering:
- Custom flat claim name ("my_orgs") for both OrganizationMembershipMapper
and OrganizationGroupMembershipMapper, verifying the claim appears at the
configured name and not at "organization"
- Dotted claim name ("custom.org") for OrganizationGroupMembershipMapper,
verifying the token contains nested otherClaims["custom"]["org"] and that
group composition is preserved
Signed-off-by: Sven-Torben Janus <sven-torben.janus@conciso.de>
---------
Signed-off-by: Sven-Torben Janus <sven-torben.janus@conciso.de>