Skip to content

Try to decode the userinfo response like a JWT - #1117

Merged
pringelmann merged 2 commits into
mainfrom
enh/noid/parse-jwt-userinfo
Oct 2, 2026
Merged

pringelmann merged 2 commits into
mainfrom
enh/noid/parse-jwt-userinfo

Conversation

@julien-nc

Copy link
Copy Markdown
Member

... if it's not a raw JSON string.

The IdP can optionally sign and/or encrypt the userinfo response. This adds support for such case.

See related feature request.

I tried it with those settings in the Keycloak client:
image

and

image

@julien-nc julien-nc added enhancement New feature or request 3. to review labels May 5, 2025
@julien-nc
julien-nc requested a review from juliusknorr May 5, 2025 15:07
@julien-nc
julien-nc force-pushed the enh/noid/parse-jwt-userinfo branch from d9c87f2 to ba69c16 Compare December 16, 2025 11:10
julien-nc and others added 2 commits September 30, 2026 14:16
Some IdPs, e.g. ProConnect, return userinfo as a signed JWT instead
of JSON. If the body isn't JSON, verify it against the provider's
JWKS and use its claims.

Signed-off-by: Julien Veyssier <julien-nc@posteo.net>
Signed-off-by: Peter Ringelmann <peter.ringelmann@nextcloud.com>
Signed-off-by: Peter Ringelmann <peter.ringelmann@nextcloud.com>
@pringelmann
pringelmann force-pushed the enh/noid/parse-jwt-userinfo branch from ba69c16 to 9d77998 Compare September 30, 2026 12:32
@pringelmann

Copy link
Copy Markdown
Contributor

Some additions:

  • rebased on main, only conflict was the userinfo warning log line
  • JSON_THROW_ON_ERROR on the JSON attempt, instead of relying on the TypeError from the array return type
  • [UserInfo] prefix on the new logs, and a warning (was debug) when the JWT decode fails
  • unit tests: plain JSON, signed JWT, JWT with a wrong key

@pringelmann
pringelmann requested a review from artonge September 30, 2026 12:39
@pringelmann
pringelmann merged commit 223f755 into main Oct 2, 2026
65 of 83 checks passed
@pringelmann
pringelmann deleted the enh/noid/parse-jwt-userinfo branch October 2, 2026 07:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants