Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: handling of user-defined jwt claims #1517

Merged
merged 1 commit into from
Feb 10, 2025
Merged

fix: handling of user-defined jwt claims #1517

merged 1 commit into from
Feb 10, 2025

Conversation

csmig
Copy link
Member

@csmig csmig commented Feb 8, 2025

Resolves #1515

  • (API) Formats config.oauth.claims.privileges to conform to MySQL JSON path syntax by double-quoting all object properties.
  • (API) Updates queries that consume config.oauth.claims.privileges to surround the path statement with single-quotes in order to support the double-quoted path components
  • (API) Renames function formatChain() to formatJsChain() for clarity
  • (API) Renames properties of config.oauth.claims for clarity:
    • privileges => privilegesChain
    • privilegesPath => privileges
  • (API) Removes oauth.claims from Env.js served to the web app since it is no longer used by any web app code
  • (API) Adds a missing const declaration in User.js
  • (API) Replaces hardcoded path $.name with $.${config.oauth.claims.name} in CollectionService.js
  • (Doc) Updates documentation of the STIGMAN_JWT_*_CLAIM environment variables to describe which variables MUST NOT be nested and MUST be valid ECMAScript identifiers, or MAY be nested and SHOULD be valid ECMAScript identifiers. STIGMAN_JWT_PRIVILEGES_CLAIM is the only variable documented as allowing nesting.

@csmig csmig added documentation Improvements or additions to documentation API UI labels Feb 8, 2025
@csmig csmig requested review from cd-rite and Matte22 February 8, 2025 17:40
Copy link

sonarqubecloud bot commented Feb 8, 2025

Quality Gate Passed Quality Gate passed for 'nuwcdivnpt_stig-manager-client'

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

Copy link

sonarqubecloud bot commented Feb 8, 2025

@csmig csmig removed the UI label Feb 8, 2025
Copy link
Collaborator

@Matte22 Matte22 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

loooks and tests good to me

@csmig csmig merged commit a348cf9 into main Feb 10, 2025
13 checks passed
@csmig csmig deleted the jwt-claims-handling branch February 10, 2025 19:21
Matte22 added a commit to Matte22/stig-manager that referenced this pull request Feb 10, 2025
* adds missed tests for metrics (NUWCDIVNPT#1500)

* test: adds missing test cases for admin and create_collection (NUWCDIVNPT#1505)

* chore: 1.5.3 updates (NUWCDIVNPT#1499)

* missing descriptions for a few detailed metrics (NUWCDIVNPT#1511)

* fix: add ruleIds to ReviewAssetRuleRead; remove String255 references (NUWCDIVNPT#1510)

* fix: on unregistering a user, clear userGroups and request userGroups projection. (NUWCDIVNPT#1514)

* fix: user-defined jwt claims handling (NUWCDIVNPT#1517)

* feat: adds users with admin privileges to home screen (NUWCDIVNPT#1520)

* test

* test

* test merge

* test

---------

Co-authored-by: cd-rite <61710958+cd-rite@users.noreply.github.com>
Co-authored-by: csmig <33138761+csmig@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
API documentation Improvements or additions to documentation
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Issues with update to 1.5.3
2 participants