Browse Source

Allow client assertion audiences to be represented as JSON arrays

pull/2547/head
Kévin Chalet 3 weeks ago
parent
commit
10195fd483
  1. 24
      src/OpenIddict.Server/OpenIddictServerHandlers.cs

24
src/OpenIddict.Server/OpenIddictServerHandlers.cs

@ -780,7 +780,7 @@ public static partial class OpenIddictServerHandlers
// For more information, see // For more information, see
// https://openid.net/specs/openid-connect-core-1_0.html#ClientAuthentication and // https://openid.net/specs/openid-connect-core-1_0.html#ClientAuthentication and
// https://datatracker.ietf.org/doc/html/rfc7523#section-3. // https://datatracker.ietf.org/doc/html/rfc7523#section-3.
if (context.ClientAssertionPrincipal.GetAudiences() is not [_]) if (context.ClientAssertionPrincipal.GetAudiences() is not [{ Length: > 0 }])
{ {
context.Reject( context.Reject(
error: Errors.InvalidRequest, error: Errors.InvalidRequest,
@ -809,15 +809,21 @@ public static partial class OpenIddictServerHandlers
static bool ValidateClaimGroup(string name, List<Claim> values) => name switch static bool ValidateClaimGroup(string name, List<Claim> values) => name switch
{ {
// The following claims MUST be represented as unique strings. // The following claims MUST be represented as unique strings or array of strings.
//
// Important: client assertions with multiple audiences was initially deliberately supported by
// the OpenID Connect and Assertion Framework for OAuth 2.0 Client Authentication specifications.
// Since 2025, using multiple audiences is no longer allowed for security reasons. As such, the
// "aud" claim present in client assertions MUST always be represented as a single string.
// //
// See https://www.ietf.org/archive/id/draft-ietf-oauth-rfc7523bis-01.html#section-4 for more information. // Note: the initial version of the "Updates to Audience Values for OAuth 2.0 Authorization Servers"
Claims.Audience or Claims.AuthorizedParty or Claims.Issuer or Claims.JwtId or Claims.Subject // specification initially required that the "aud" claim be represented as a unique string but more
// recent versions of the specification allow the "aud" claim to be represented as a JSON array of strings.
Claims.Audience => values.TrueForAll(static value => value.ValueType is ClaimValueTypes.String) ||
// Note: a unique claim using the special JSON_ARRAY claim value type is allowed
// if the individual elements of the parsed JSON array are all string values.
(values is [{ ValueType: JsonClaimValueTypes.JsonArray, Value: string value }] &&
JsonSerializer.Deserialize(value, OpenIddictSerializer.Default.JsonElement)
is { ValueKind: JsonValueKind.Array } element &&
OpenIddictHelpers.ValidateArrayElements(element, JsonValueKind.String)),
// The following claims MUST be represented as unique strings.
Claims.AuthorizedParty or Claims.Issuer or Claims.JwtId or Claims.Subject
=> values is [{ ValueType: ClaimValueTypes.String }], => values is [{ ValueType: ClaimValueTypes.String }],
// The following claims MUST be represented as unique numeric dates. // The following claims MUST be represented as unique numeric dates.

Loading…
Cancel
Save