fix: update OIDC hooks and clear traits for registration flow - #910
Open
giriparus wants to merge 1 commit into
Open
fix: update OIDC hooks and clear traits for registration flow#910giriparus wants to merge 1 commit into
giriparus wants to merge 1 commit into
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
Mitigates OIDC registration “squatting” in the Identity Platform Login UI by ensuring email/traits used during OIDC registration come from IdP-verified claims and by aligning Kratos OIDC post-registration hooks with the password flow.
Changes:
- Drops any client-supplied
traitswhen updating a Kratos registration flow using theoidcmethod. - Adds the
show_verification_uihook to Kratos’registration.after.oidc.hooks(matching the password flow’s hooks).
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
pkg/kratos/service.go |
Clears UpdateRegistrationFlowWithOidcMethod.Traits during parsing to prevent client-provided traits from overriding IdP claims. |
docker/kratos/kratos.yml |
Adds show_verification_ui to OIDC registration “after” hooks to mirror password registration behavior. |
Comment on lines
999
to
1009
| case "oidc": | ||
| var body kClient.UpdateRegistrationFlowWithOidcMethod | ||
| if err := parseBody(r.Body, &body); err != nil { | ||
| return nil, err | ||
| } | ||
| // Traits for OIDC registration must come from IdP-verified claims | ||
| // (docker/kratos/schema.jsonnet), never from client input. Without this, | ||
| // the identifier-first email (xxx@email.com) overrides the provider email | ||
| // (yyy@gmail.com) and the account registers under an unproven address. | ||
| body.Traits = nil | ||
| ret = kClient.UpdateRegistrationFlowWithOidcMethodAsUpdateRegistrationFlowBody(&body) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Resolutions