feat(auth): discover OIDC authorize and token endpoints - #262
Open
AdamClaassens wants to merge 1 commit into
Open
AdamClaassens wants to merge 1 commit into
AdamClaassens wants to merge 1 commit into
Conversation
OpenClaw ID still concatenates {issuer}/oauth2/* as the default. Other
issuers, including Kanidm, publish different authorization and token
paths. Fetch OpenID Connect discovery at serve startup and fail closed
when a custom issuer has no usable document.
Contributor
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review blockedAutomated review did not run, so no review verdict was produced. Reason: The input-safety check rejected material in this revision. No detected value, path, or scanner output is reproduced here. ClawSweeper will not retry this unchanged revision. Next step: If this is a genuine credential, remove and rotate it. If it is an intentional test fixture, a maintainer must review and qualify it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ClickClack's OpenClaw ID client currently derives
AuthURL/TokenURLas{issuer}/oauth2/authorizeand{issuer}/oauth2/token. That matches OpenClaw ID. It does not match Kanidm's OpenID Connect discovery document, whereauthorization_endpointis/ui/oauth2andtoken_endpointis/oauth2/tokenwhileissueris/oauth2/openid/:client_id:.This change GETs
<issuer>/.well-known/openid-configurationat serve startup (no redirects), requires the documentissuerto matchOPENCLAW_ID_ISSUER, and uses the published endpoints. The default OpenClaw ID issuer may still fall back to concatenated paths when discovery is absent. Any other issuer fails closed. ExplicitAuthURLandTokenURLskip the fetch.Tests cover a Kanidm-shaped discovery document, mismatch, missing document, default fallback, and explicit endpoints.