Mercurial > prosody-modules
view mod_groups_oidc/mod_groups_oidc.lua @ 5643:73c3d5bfce3e
mod_http_oauth2: Allow 'login_hint' as a substitute for OIDC 'select_account' prompt
If the OIDC 'prompt' parameter does not contain the 'select_account'
then it wants us to skip account selection, which means we have to
figure which account to authenticate somehow. One way could be have
this stored in a cookie from a previous successful login. Another way
would be to have the account passed as a hint, which is what we add
here.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Sat, 09 Sep 2023 21:42:24 +0200 |
parents | 7d9dce4e7dd0 |
children |
line wrap: on
line source
local array = require "util.array"; module:add_item("openid-claim", "groups"); local group_memberships = module:open_store("groups", "map"); local function user_groups(username) return pairs(group_memberships:get_all(username) or {}); end module:hook("token/userinfo", function(event) local userinfo = event.userinfo; if event.claims:contains("groups") then userinfo.groups = array(user_groups(event.username)); end end);