Repository navigation
Conversation
…mized The common-tenant issuer rewrite and token-body error handling were gated on provider.id matching microsoft-entra-id or azure-ad, so a custom id skipped the hacks. Identify Entra by issuer instead. Fixes nextauthjs#13171
|
The latest updates on your projects. Learn more about Vercel for GitHub.
1 Skipped Deployment
|
|
@cpruijsen is attempting to deploy a commit to the authjs Team on Vercel. A member of the Team first needs to authorize it. |
Author
|
Closing this. Not something I'm going to keep current. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reasoning
Microsoft Entra ID common-tenant workarounds (token-body errors and re-discovery from the
id_tokentidclaim) now run whenconformInternalis set and either the id is stillmicrosoft-entra-idorazure-ad, or the authorization-server issuer looks like Microsoft (microsoftonlinein the issuer URL).The workarounds previously ran only when
provider.idwasmicrosoft-entra-idorazure-ad. Auth.js allows overridingid; that override is merged inparseProvidersand is used for callback URLs. A GraphQL-safe id such asmicrosoft_entra_idskipped the hacks added in #11980, while[conformInternal]and the{tenantid}discovery rewrite on the provider itself still ran.Apple also sets
conformInternalbut useshttps://appleid.apple.com, so it is unchanged.Entra is identified by issuer (plus the two default ids), not by adding
microsoft_entra_idas anotherswitchcase. The reporter's expected behavior is that any custom id keeps the hacks;microsoft_entra_idwas only their GraphQL example, and one extra spelling would miss the next enum-safe name. Can switch to an explicit id allow-list if that is preferred.The common-tenant approach is the one from #11980; this only stops a custom
idfrom disabling it.Checklist
Affected issues
Fixes: #13171
Resources