This repository has been archived on 2024-05-31. You can view files and clone it, but cannot push or open issues or pull requests.
authentik/blueprints/default
Jens L 80f4fccd35
providers/oauth2: OpenID conformance (#4758)
* don't open inspector by default when debug is enabled

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* encode error in fragment when using hybrid grant_type

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* require nonce for all response_types that get an id_token from the authorization endpoint

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* don't set empty family_name

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* only set at_hash when response has token

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* cleaner way to get login time

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* remove authentication requirement from authentication flow

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* use wrapper

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* fix auth_time not being handled correctly

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* minor cleanup

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* add test files

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* fix tests

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* remove USER_LOGIN_AUTHENTICATED

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* rework prompt=login handling

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* also set last login uid for max_age check to prevent double login when max_age and prompt=login is set

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

---------

Signed-off-by: Jens Langhammer <jens@goauthentik.io>
2023-02-23 15:26:41 +01:00
..
default-tenant.yaml blueprints: don't update default tenant 2023-01-31 15:17:05 +01:00
events-default.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-default-authentication-flow.yaml providers/oauth2: OpenID conformance (#4758) 2023-02-23 15:26:41 +01:00
flow-default-authenticator-static-setup.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-default-authenticator-totp-setup.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-default-authenticator-webauthn-setup.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-default-invalidation-flow.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-default-provider-authorization-explicit-consent.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-default-provider-authorization-implicit-consent.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-default-source-authentication.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-default-source-enrollment.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-default-source-pre-authentication.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-default-user-settings-flow.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-oobe.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00
flow-password-change.yaml stages/prompt: field name (#4497) 2023-01-24 12:23:22 +01:00