Skip to content

fix(core): keep Microsoft Entra workarounds when provider id is customized - #13496

Closed
cpruijsen wants to merge 1 commit into
nextauthjs:mainfrom
cpruijsen:fix/issue-13171
Closed

cpruijsen wants to merge 1 commit into
nextauthjs:mainfrom
cpruijsen:fix/issue-13171

Conversation

@cpruijsen

Copy link
Copy Markdown

Reasoning

Microsoft Entra ID common-tenant workarounds (token-body errors and re-discovery from the id_token tid claim) now run when conformInternal is set and either the id is still microsoft-entra-id or azure-ad, or the authorization-server issuer looks like Microsoft (microsoftonline in the issuer URL).

The workarounds previously ran only when provider.id was microsoft-entra-id or azure-ad. Auth.js allows overriding id; that override is merged in parseProviders and is used for callback URLs. A GraphQL-safe id such as microsoft_entra_id skipped the hacks added in #11980, while [conformInternal] and the {tenantid} discovery rewrite on the provider itself still ran.

Apple also sets conformInternal but uses https://appleid.apple.com, so it is unchanged.

Entra is identified by issuer (plus the two default ids), not by adding microsoft_entra_id as another switch case. The reporter's expected behavior is that any custom id keeps the hacks; microsoft_entra_id was only their GraphQL example, and one extra spelling would miss the next enum-safe name. Can switch to an explicit id allow-list if that is preferred.

The common-tenant approach is the one from #11980; this only stops a custom id from disabling it.

Checklist

  • Documentation
  • Tests
  • Ready to be merged

Affected issues

Fixes: #13171

Resources

…mized

The common-tenant issuer rewrite and token-body error handling were
gated on provider.id matching microsoft-entra-id or azure-ad, so a
custom id skipped the hacks. Identify Entra by issuer instead.

Fixes nextauthjs#13171
@vercel

vercel Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
auth-docs Ready Ready Preview Sep 11, 2026 8:29am UTC
1 Skipped Deployment
Project Deployment Actions Updated
next-auth-docs Ignored Ignored Preview Sep 11, 2026 8:29am UTC

Request Review

@vercel

vercel Bot commented Sep 11, 2026

Copy link
Copy Markdown

@cpruijsen is attempting to deploy a commit to the authjs Team on Vercel.

A member of the Team first needs to authorize it.

@cpruijsen

Copy link
Copy Markdown
Author

Closing this. Not something I'm going to keep current.

@cpruijsen cpruijsen closed this Oct 1, 2026

This branch was successfully deployed

1 active deployment
Preview – auth-docs — d90008a8 Deployed Sep 11, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core Refers to `@auth/core`

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Microsoft common tenant OAuth hacks don't work if you customize the provider ID

1 participant