-
Notifications
You must be signed in to change notification settings - Fork 2.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support custom Authorization schemes for OIDC bearer tokens #37166
Support custom Authorization schemes for OIDC bearer tokens #37166
Conversation
✔️ The latest workflow run for the pull request has completed successfully. It should be safe to merge provided you have a look at the other checks in the summary. |
Hi @pedroigor This is one is quite simple, there are cases where tokens are arriving ex as The only reason this PR is a bit more involved than it should otherwise be, is that with this customization we have to correctly represent the bearer token challenge and HTTP transport metadata, but it was simple enough to fix |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Thanks @pedroigor |
This MR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [flow-bin](https://github.com/flowtype/flow-bin) ([changelog](https://github.com/facebook/flow/blob/master/Changelog.md)) | devDependencies | minor | [`^0.222.0` -> `^0.223.0`](https://renovatebot.com/diffs/npm/flow-bin/0.222.0/0.223.2) | | [io.quarkus:quarkus-maven-plugin](https://github.com/quarkusio/quarkus) | build | minor | `3.5.3` -> `3.6.0` | | [io.quarkus:quarkus-universe-bom](https://github.com/quarkusio/quarkus-platform) | import | minor | `3.5.3` -> `3.6.0` | --- ### Release Notes <details> <summary>flowtype/flow-bin</summary> ### [`v0.223.2`](flow/flow-bin@5bb7bcf...6e1e3f7) [Compare Source](flow/flow-bin@5bb7bcf...6e1e3f7) ### [`v0.223.0`](flow/flow-bin@84a68f1...5bb7bcf) [Compare Source](flow/flow-bin@84a68f1...5bb7bcf) </details> <details> <summary>quarkusio/quarkus</summary> ### [`v3.6.0`](https://github.com/quarkusio/quarkus/releases/tag/3.6.0) [Compare Source](quarkusio/quarkus@3.5.3...3.6.0) ##### Major changes - [#​37241](quarkusio/quarkus#37241) - Make improvements to REST Client SSE handling ##### Complete changelog - [#​37242](quarkusio/quarkus#37242) - Support Docker Desktop for building native executables - [#​37241](quarkusio/quarkus#37241) - Make improvements to REST Client SSE handling - [#​37240](quarkusio/quarkus#37240) - Updates Infinispan to 14.0.21.Final - [#​37238](quarkusio/quarkus#37238) - Build cache - Only store if the access key is around - [#​37236](quarkusio/quarkus#37236) - Api to read minimum and recommended Java versions from catalog metadata - [#​37221](quarkusio/quarkus#37221) - Image updates (including Java 21 base image) - [#​37218](quarkusio/quarkus#37218) - Fix OpenTelemetry trace exclusion of endpoints served from the management interface - [#​37213](quarkusio/quarkus#37213) - Add basic Range header support - [#​37205](quarkusio/quarkus#37205) - Resteasy-reactive Partial Content support (Range: bytes http header) - [#​37204](quarkusio/quarkus#37204) - Allow to define allowed roles as configuration expressions inside `@SecureField` annotation - [#​37201](quarkusio/quarkus#37201) - Fixed sample code for KotlinModule initialization - [#​37198](quarkusio/quarkus#37198) - Some minor refinements for build scans - [#​37193](quarkusio/quarkus#37193) - AccessDeniedException error with build using native image on linux with Docker Desktop - [#​37185](quarkusio/quarkus#37185) - Removed DependencyFlags.REMOVED - [#​37170](quarkusio/quarkus#37170) - Fix snapshots following a collision of pull requests - [#​37166](quarkusio/quarkus#37166) - Support custom Authorization schemes for OIDC bearer tokens - [#​37162](quarkusio/quarkus#37162) - Bump org.apache.commons:commons-text from 1.10.0 to 1.11.0 - [#​37161](quarkusio/quarkus#37161) - Bump io.quarkus:quarkus-platform-bom-maven-plugin from 0.0.97 to 0.0.99 - [#​37158](quarkusio/quarkus#37158) - Bump com.unboundid:unboundid-ldapsdk from 6.0.9 to 6.0.10 - [#​37153](quarkusio/quarkus#37153) - Bump smallrye-jwt version to 4.4.0 - [#​37149](quarkusio/quarkus#37149) - Bump com.squareup.okio:okio from 1.17.2 to 1.17.6 in /bom/application - [#​37107](quarkusio/quarkus#37107) - Rest client able to get full SSE event - [#​37101](quarkusio/quarkus#37101) - Remove `smallrye-opentracing` from native tests modules in CI - [#​37094](quarkusio/quarkus#37094) - Bump jakarta.json:jakarta.json-api from 2.1.2 to 2.1.3 - [#​37092](quarkusio/quarkus#37092) - Bump mongo-client.version from 4.11.0 to 4.11.1 - [#​37067](quarkusio/quarkus#37067) - SmallRye GraphQL 2.6 + custom scalar registration - [#​37053](quarkusio/quarkus#37053) - Clarify dynamic Environment Variables name conversion - [#​37004](quarkusio/quarkus#37004) - Move failsafe config to the root instead of in an execution - [#​36976](quarkusio/quarkus#36976) - Error in JBossLoggerFinder during integration test - [#​36804](quarkusio/quarkus#36804) - `@SecureField` add expression support - [#​36801](quarkusio/quarkus#36801) - Add note that endpointdisabled does not work native - [#​36746](quarkusio/quarkus#36746) - Allow using a random test port within Google Cloud Function tests - [#​35476](quarkusio/quarkus#35476) - Random test port does not work together with google-cloud-functions extensions </details> <details> <summary>quarkusio/quarkus-platform</summary> ### [`v3.6.0`](quarkusio/quarkus-platform@3.5.3...3.6.0) [Compare Source](quarkusio/quarkus-platform@3.5.3...3.6.0) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever MR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This MR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNC4yNC4wIiwidXBkYXRlZEluVmVyIjoiMzQuMjQuMCJ9-->
Simple PR to support custom HTTP Authorization header schemes. Typically it is
Bearer
but there could be cases, where a different scheme is used.FYI, Quarkus OIDC already supports custom headers (different to
Authorization
), this PR allows to fine tune howAuthorization
headers are handled/cc @calvernaz.
Note there will be a dedicated enhancement to support propagating using the custom schemes, as well as ID tokens