[PR #2663] [MERGED] OIDC: Query userinfo endpoint before verifying user #2789

Closed
opened 2025-12-29 04:18:58 +01:00 by adam · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/juanfont/headscale/pull/2663
Author: @fredrikekre
Created: 6/27/2025
Status: Merged
Merged: 8/11/2025
Merged by: @nblock

Base: mainHead: fe/userinfo-groups


📝 Commits (1)

  • 24e964c OIDC: Query userinfo endpoint before verifying user

📊 Changes

3 files changed (+34 additions, -24 deletions)

View changed files

📝 CHANGELOG.md (+4 -0)
📝 hscontrol/oidc.go (+29 -24)
📝 hscontrol/types/users.go (+1 -0)

📄 Description

This patch includes some changes to the OIDC integration in particular:

  • Make sure that userinfo claims are queried before comparing the user with the configured allowed groups, email and email domain.
  • Update user with group claim from the userinfo endpoint which is required for allowed groups to work correctly. This is essentially a continuation of #2545.
  • Let userinfo claims take precedence over id token claims.

With these changes I have verified that Headscale works as expected together with Authelia without the documented escape hatch 0, i.e. everything works even if the id token only contain the iss and sub claims.

  • have read the CONTRIBUTING.md file
  • raised a GitHub issue or discussed it on the projects chat beforehand
  • added unit tests
  • added integration tests
  • updated documentation if needed
  • updated CHANGELOG.md

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/juanfont/headscale/pull/2663 **Author:** [@fredrikekre](https://github.com/fredrikekre) **Created:** 6/27/2025 **Status:** ✅ Merged **Merged:** 8/11/2025 **Merged by:** [@nblock](https://github.com/nblock) **Base:** `main` ← **Head:** `fe/userinfo-groups` --- ### 📝 Commits (1) - [`24e964c`](https://github.com/juanfont/headscale/commit/24e964ccbcda61d73011f5712ca7878800bfb00b) OIDC: Query userinfo endpoint before verifying user ### 📊 Changes **3 files changed** (+34 additions, -24 deletions) <details> <summary>View changed files</summary> 📝 `CHANGELOG.md` (+4 -0) 📝 `hscontrol/oidc.go` (+29 -24) 📝 `hscontrol/types/users.go` (+1 -0) </details> ### 📄 Description This patch includes some changes to the OIDC integration in particular: - Make sure that userinfo claims are queried *before* comparing the user with the configured allowed groups, email and email domain. - Update user with group claim from the userinfo endpoint which is required for allowed groups to work correctly. This is essentially a continuation of #2545. - Let userinfo claims take precedence over id token claims. With these changes I have verified that Headscale works as expected together with Authelia without the documented escape hatch [0], i.e. everything works even if the id token only contain the iss and sub claims. [0]: https://www.authelia.com/integration/openid-connect/headscale/#configuration-escape-hatch <!-- Headscale is "Open Source, acknowledged contribution", this means that any contribution will have to be discussed with the Maintainers before being submitted. This model has been chosen to reduce the risk of burnout by limiting the maintenance overhead of reviewing and validating third-party code. Headscale is open to code contributions for bug fixes without discussion. If you find mistakes in the documentation, please submit a fix to the documentation. --> <!-- Please tick if the following things apply. You… --> - [x] have read the [CONTRIBUTING.md](./CONTRIBUTING.md) file - [x] raised a GitHub issue or discussed it on the projects chat beforehand - [ ] added unit tests - [ ] added integration tests - [ ] updated documentation if needed - [x] updated CHANGELOG.md <!-- If applicable, please reference the issue using `Fixes #XXX` and add tests to cover your new code. --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
adam added the pull-request label 2025-12-29 04:18:58 +01:00
adam closed this issue 2025-12-29 04:18:59 +01:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/headscale#2789