Repository navigation
fix: enforce DCR registration policy for device clients [DHIS2-19948] - #25470
Merged
Merged
Conversation
Clients registered through OAuth2 Dynamic Client Registration (/connect/register) must match the DHIS2 Android device profile. - Add DcrRegistrationPolicyValidator, chained after Spring Authorization Server's default registration validator. A registration must use the redirect URI of its initial access token, the authorization_code grant (optionally refresh_token), response type code and private_key_jwt client authentication, without post-logout redirect URIs. The subject of the initial access token must be an active user. - Dhis2OAuth2ClientServiceImpl.save(RegisteredClient) applies the grant-type and scope rules and the active-subject check to clients saved with an initial access token. - The token customizer no longer adds a username claim to client_credentials tokens. - Add IAT_REDIRECT_URL_CLAIM to OAuth2Constants, used when issuing and checking initial access tokens.
This was referenced Oct 1, 2026
|
jbee
approved these changes
Oct 5, 2026
netroms
enabled auto-merge (squash)
October 7, 2026 12:41
vietnguyen
approved these changes
Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Clients registered through OAuth2 Dynamic Client Registration (
POST /connect/register) mustmatch the DHIS2 Android device profile.
Registration policy
DcrRegistrationPolicyValidatorruns after Spring Authorization Server's default registrationvalidator and requires:
redirect_uris: exactly the redirect URI of the initial access token (redirect_urlclaim)grant_types:authorization_code, optionallyrefresh_tokenresponse_types:codetoken_endpoint_auth_method:private_key_jwtpost_logout_redirect_urisOther registrations get an RFC 7591 error (
invalid_client_metadata/invalid_redirect_uri,invalid_tokenfor an inactive subject) and nothing is persisted. The DHIS2 Android SDKregistration request matches this profile.
Also:
Dhis2OAuth2ClientServiceImpl.save(RegisteredClient)applies the grant-type and scope rules andthe active-subject check to clients saved with an initial access token.
OAuth2Constants.IAT_REDIRECT_URL_CLAIMis shared by the code that issues and checks initialaccess tokens.
Tests
DcrControllerTest.java(H2, through the Spring Authorization Server filter chain; the class inthat file is
DcrWithJwksTeston 2.42):authorization_code(+
refresh_token), redirect URIs other than the IAT redirect, client authentication other thanprivate_key_jwt(including none given), post-logout redirect URIs/api/auth/enrollDeviceand registersthe device client
client_credentialstokens carry nousernameclaim and are not accepted for API requestssave()refuses aclient_credentialsclientprivate_key_jwtand calls the APIclient_credentialsResults on the PR heads,
org.hisp.dhis.webapi.controller.securitypackage: master 91/91,2.43 88/88, 2.42 88/88.
spotless:checkanddependency:analyze-onlypass on all three.Related PRs
Same change on the other lines:
2.43: fix: enforce DCR registration policy for device clients [DHIS2-19948] #254712.42: fix: enforce DCR registration policy for device clients [DHIS2-19948] #25472