Edit history

Earlier versions of [Self-Hosted] SSO validation fails when OIDC provider returns issuer without trailing slash, newest first.

Current version | Edited by Rex
Changes
When set issuer-url like: https://domain.com/ and it doesnt match with the provider issuer: https://domain.comRemoved: ### EnvironmentRemoved: Removed: _No response_Removed: ### Logs or screenshots```api-1 | {"level":"error","time":"DATE:TIME","service":"fluxer-api","env":"production","logger":"SsoService","error":{"type":"JWTClaimValidationFailed","message":"unexpected \"iss\" claim value","stack":"JWTClaimValidationFailed: unexpected \"iss\" claim value\n at validateClaimsSet (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/lib/jwt_claims_set.js:114:15)\n at jwtVerify (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/jwt/verify.js:9:21)\n at async SsoService.verifyIdToken (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:624:23)\n at async SsoService.resolveClaims (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:566:14)\n at async SsoService.completeLogin (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:332:18)\n at async AuthRequestService.toSsoCompleteResponse (/usr/src/app/fluxer_api/src/api/auth/AuthRequestService.ts:386:18)\n at async Object.handler (/usr/src/app/fluxer_api/src/api/auth/AuthController.ts:104:19)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)\n at async handler (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/hono-base.js:118:39)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)","code":"ERR_JWT_CLAIM_VALIDATION_FAILED","name":"JWTClaimValidationFailed","claim":"iss","reason":"check_failed","payload":{"amr":["phr"]```Removed: Removed: ### ChecksRemoved: Removed: - ☑ I searched existing issues.Removed: - ☑ I wrote this report in my own words, except for direct translation if needed.
Show

[Self-Hosted] SSO validation fails when OIDC provider returns issuer without trailing slash

Summary

When I use SSO from PocketID, the app_url is https://domain.com/ without a trailing slash. It works everywhere, except with Fluxer. When I configured it in the WebGUI, it automatically adds a trailing slash. So, when those 2 aren't the same, it gives an error: Invalid SSO Token. With the error being: JWTClaimValidationFailed: unexpected "iss" claim value claim: "iss" reason: "check_failed"

Steps to reproduce

Login SSO Use the button Use key Get error. When set issuer-url like: https://domain.com/ and it doesnt match with the provider issuer: https://domain.com/

Logs or screenshots

api-1 | {"level":"error","time":"DATE:TIME","service":"fluxer-api","env":"production","logger":"SsoService","error":{"type":"JWTClaimValidationFailed","message":"unexpected \"iss\" claim value","stack":"JWTClaimValidationFailed: unexpected \"iss\" claim value\n at validateClaimsSet (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/lib/jwt_claims_set.js:114:15)\n at jwtVerify (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/jwt/verify.js:9:21)\n at async SsoService.verifyIdToken (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:624:23)\n at async SsoService.resolveClaims (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:566:14)\n at async SsoService.completeLogin (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:332:18)\n at async AuthRequestService.toSsoCompleteResponse (/usr/src/app/fluxer_api/src/api/auth/AuthRequestService.ts:386:18)\n at async Object.handler (/usr/src/app/fluxer_api/src/api/auth/AuthController.ts:104:19)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)\n at async handler (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/hono-base.js:118:39)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)","code":"ERR_JWT_CLAIM_VALIDATION_FAILED","name":"JWTClaimValidationFailed","claim":"iss","reason":"check_failed","payload":{"amr":["phr"]
Edited by Rex
Changes
```api-1 | {"level":"error","time":"DATE:TIME","service":"fluxer-api","env":"production","logger":"SsoService","error":{"type":"JWTClaimValidationFailed","message":"unexpected \"iss\" claim value","stack":"JWTClaimValidationFailed: unexpected \"iss\" claim value\n at validateClaimsSet (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/lib/jwt_claims_set.js:114:15)\n at jwtVerify (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/jwt/verify.js:9:21)\n at async SsoService.verifyIdToken (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:624:23)\n at async SsoService.resolveClaims (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:566:14)\n at async SsoService.completeLogin (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:332:18)\n at async AuthRequestService.toSsoCompleteResponse (/usr/src/app/fluxer_api/src/api/auth/AuthRequestService.ts:386:18)\n at async Object.handler (/usr/src/app/fluxer_api/src/api/auth/AuthController.ts:104:19)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)\n at async handler (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/hono-base.js:118:39)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)","code":"ERR_JWT_CLAIM_VALIDATION_FAILED","name":"JWTClaimValidationFailed","claim":"iss","reason":"check_failed","payload":{"amr":["phr"]Added: ```### Checks
Show

[Self-Hosted] SSO validation fails when OIDC provider returns issuer without trailing slash

Summary

When I use SSO from PocketID, the app_url is https://domain.com/ without a trailing slash. It works everywhere, except with Fluxer. When I configured it in the WebGUI, it automatically adds a trailing slash. So, when those 2 aren't the same, it gives an error: Invalid SSO Token. With the error being: JWTClaimValidationFailed: unexpected "iss" claim value claim: "iss" reason: "check_failed"

Steps to reproduce

Login SSO Use the button Use key Get error. When set issuer-url like: https://domain.com/ and it doesnt match with the provider issuer: https://domain.com/

Environment

No response

Logs or screenshots

api-1 | {"level":"error","time":"DATE:TIME","service":"fluxer-api","env":"production","logger":"SsoService","error":{"type":"JWTClaimValidationFailed","message":"unexpected \"iss\" claim value","stack":"JWTClaimValidationFailed: unexpected \"iss\" claim value\n at validateClaimsSet (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/lib/jwt_claims_set.js:114:15)\n at jwtVerify (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/jwt/verify.js:9:21)\n at async SsoService.verifyIdToken (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:624:23)\n at async SsoService.resolveClaims (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:566:14)\n at async SsoService.completeLogin (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:332:18)\n at async AuthRequestService.toSsoCompleteResponse (/usr/src/app/fluxer_api/src/api/auth/AuthRequestService.ts:386:18)\n at async Object.handler (/usr/src/app/fluxer_api/src/api/auth/AuthController.ts:104:19)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)\n at async handler (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/hono-base.js:118:39)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)","code":"ERR_JWT_CLAIM_VALIDATION_FAILED","name":"JWTClaimValidationFailed","claim":"iss","reason":"check_failed","payload":{"amr":["phr"]

Checks

  • ☑ I searched existing issues.
  • ☑ I wrote this report in my own words, except for direct translation if needed.
Edited by Rex
Changes
### Logs or screenshotsAdded: ```api-1 | {"level":"error","time":"DATE:TIME","service":"fluxer-api","env":"production","logger":"SsoService","error":{"type":"JWTClaimValidationFailed","message":"unexpected \"iss\" claim value","stack":"JWTClaimValidationFailed: unexpected \"iss\" claim value\n at validateClaimsSet (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/lib/jwt_claims_set.js:114:15)\n at jwtVerify (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/jwt/verify.js:9:21)\n at async SsoService.verifyIdToken (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:624:23)\n at async SsoService.resolveClaims (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:566:14)\n at async SsoService.completeLogin (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:332:18)\n at async AuthRequestService.toSsoCompleteResponse (/usr/src/app/fluxer_api/src/api/auth/AuthRequestService.ts:386:18)\n at async Object.handler (/usr/src/app/fluxer_api/src/api/auth/AuthController.ts:104:19)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)\n at async handler (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/hono-base.js:118:39)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)","code":"ERR_JWT_CLAIM_VALIDATION_FAILED","name":"JWTClaimValidationFailed","claim":"iss","reason":"check_failed","payload":{"amr":["phr"]
Show

[Self-Hosted] SSO validation fails when OIDC provider returns issuer without trailing slash

Summary

When I use SSO from PocketID, the app_url is https://domain.com/ without a trailing slash. It works everywhere, except with Fluxer. When I configured it in the WebGUI, it automatically adds a trailing slash. So, when those 2 aren't the same, it gives an error: Invalid SSO Token. With the error being: JWTClaimValidationFailed: unexpected "iss" claim value claim: "iss" reason: "check_failed"

Steps to reproduce

Login SSO Use the button Use key Get error. When set issuer-url like: https://domain.com/ and it doesnt match with the provider issuer: https://domain.com/

Environment

No response

Logs or screenshots

``` api-1 | {"level":"error","time":"DATE:TIME","service":"fluxer-api","env":"production","logger":"SsoService","error":{"type":"JWTClaimValidationFailed","message":"unexpected \"iss\" claim value","stack":"JWTClaimValidationFailed: unexpected \"iss\" claim value\n at validateClaimsSet (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/lib/jwt_claims_set.js:114:15)\n at jwtVerify (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/jwt/verify.js:9:21)\n at async SsoService.verifyIdToken (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:624:23)\n at async SsoService.resolveClaims (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:566:14)\n at async SsoService.completeLogin (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:332:18)\n at async AuthRequestService.toSsoCompleteResponse (/usr/src/app/fluxer_api/src/api/auth/AuthRequestService.ts:386:18)\n at async Object.handler (/usr/src/app/fluxer_api/src/api/auth/AuthController.ts:104:19)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)\n at async handler (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/hono-base.js:118:39)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)","code":"ERR_JWT_CLAIM_VALIDATION_FAILED","name":"JWTClaimValidationFailed","claim":"iss","reason":"check_failed","payload":{"amr":["phr"]

Checks

  • ☑ I searched existing issues.
  • ☑ I wrote this report in my own words, except for direct translation if needed.
Original by Rex
Show

[Self-Hosted] SSO validation fails when OIDC provider returns issuer without trailing slash

Summary

When I use SSO from PocketID, the app_url is https://domain.com/ without a trailing slash. It works everywhere, except with Fluxer. When I configured it in the WebGUI, it automatically adds a trailing slash. So, when those 2 aren't the same, it gives an error: Invalid SSO Token. With the error being: JWTClaimValidationFailed: unexpected "iss" claim value claim: "iss" reason: "check_failed"

Steps to reproduce

Login SSO Use the button Use key Get error. When set issuer-url like: https://domain.com/ and it doesnt match with the provider issuer: https://domain.com/

Environment

No response

Logs or screenshots

api-1 | {"level":"error","time":"DATE:TIME","service":"fluxer-api","env":"production","logger":"SsoService","error":{"type":"JWTClaimValidationFailed","message":"unexpected \"iss\" claim value","stack":"JWTClaimValidationFailed: unexpected \"iss\" claim value\n at validateClaimsSet (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/lib/jwt_claims_set.js:114:15)\n at jwtVerify (file:///usr/src/app/fluxer_api/node_modules/.pnpm/jose@6.1.3/node_modules/jose/dist/webapi/jwt/verify.js:9:21)\n at async SsoService.verifyIdToken (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:624:23)\n at async SsoService.resolveClaims (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:566:14)\n at async SsoService.completeLogin (/usr/src/app/fluxer_api/src/api/auth/services/SsoService.ts:332:18)\n at async AuthRequestService.toSsoCompleteResponse (/usr/src/app/fluxer_api/src/api/auth/AuthRequestService.ts:386:18)\n at async Object.handler (/usr/src/app/fluxer_api/src/api/auth/AuthController.ts:104:19)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)\n at async handler (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/hono-base.js:118:39)\n at async dispatch (file:///usr/src/app/fluxer_api/node_modules/.pnpm/hono@4.12.2/node_modules/hono/dist/compose.js:22:17)","code":"ERR_JWT_CLAIM_VALIDATION_FAILED","name":"JWTClaimValidationFailed","claim":"iss","reason":"check_failed","payload":{"amr":["phr"]

Checks

  • ☑ I searched existing issues.
  • ☑ I wrote this report in my own words, except for direct translation if needed.