replace colon in claim headers to prevent issues with namespaced claims #184
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Workaround/Fix for #183. Please see #183 for a more detailed description of the issue.
This PR rewrites any colon in a claim key to a dash. This resolves the issue that the remainder after the colon would be interpreted as part of the value instead of the key.
given a claim
custom:roles
with valueadministrator
expected result: a header
X-Vouch-IdP-Claims-custom:roles
with valueadministrator
actual result: a header
X-Vouch-IdP-Claims-custom
with valueroles: administrator
patched result: a header
X-Vouch-IdP-Claims-custom-roles
with valueadministrator
This PR is mostly provided for other users until a proper fix has been made, as anyone using custom claims with AWS Cognito (and possibly other IdPs) can easily run into the issue.