Skip to content

Accept Entra ID app roles as scopes - #85

Open
jamesdidathing wants to merge 1 commit into
ukaea:mainfrom
jamesdidathing:entra-roles-as-scopes
Open

jamesdidathing wants to merge 1 commit into
ukaea:mainfrom
jamesdidathing:entra-roles-as-scopes

Conversation

@jamesdidathing

Copy link
Copy Markdown

What this changes

Fixes #35

FDS should now read the Entra ID "roles" claim alongside scp/scope and merge them into one list of effective scopes. The merged list goes through the existing allowed-scopes filter.

How it was tested

  • tests/auth/test_security.py: roles merged with scp (including a duplicate), and a roles-only token.
  • tests/auth/test_multi_idp.py: roles outside the issuers allowed_scopes are stripped.
  • All three new tests fail without the change.
  • By hand: a locally signed token carrying only "roles": ["fds-admin"] was refused (403) by the current image and authorised with this change

Checklist

  • uv run ruff check . and uv run ruff format --check . pass
  • uv run pyright passes
  • uv run --all-extras pytest passes
  • Tests cover the change
  • Documentation updated, if the change is user-visible (no page documents which claims supply scopes)
  • Authorisation checks, if any, live in the service layer rather than the router

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Merge Entra ID roles and OIDC scp Claims for Authorisation

1 participant