providers/oauth2: fix kid always required for federation#17914
Merged
Conversation
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
✅ Deploy Preview for authentik-storybook canceled.
|
✅ Deploy Preview for authentik-integrations canceled.
|
✅ Deploy Preview for authentik-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
❌ 2 Tests Failed:
View the full list of 2 ❄️ flaky test(s)
To view more test analytics, go to the Test Analytics Dashboard |
authentik-automation bot
pushed a commit
that referenced
this pull request
Nov 3, 2025
Signed-off-by: Jens Langhammer <jens@goauthentik.io>
Contributor
|
🍒 Cherry-pick to |
BeryJu
added a commit
that referenced
this pull request
Nov 3, 2025
kensternberg-authentik
added a commit
that referenced
this pull request
Nov 10, 2025
* main: (32 commits) website/docs: 2025.10.1 release notes (#17918) providers/oauth2: fix kid always required for federation (#17914) providers/radius: revert fix inverted message authenticator validation (#17855) (#17915) website: bump @types/node from 24.9.1 to 24.9.2 in /website (#17786) web: bump @rollup/plugin-commonjs from 28.0.8 to 28.0.9 in /web in the rollup group across 1 directory (#17788) web: bump validator from 13.15.15 to 13.15.20 in /packages/docusaurus-config (#17866) internal: add default go http server timeouts (#17858) providers/radius: fix inverted message authenticator validation (#17855) stages/authenticator_webauthn: Update FIDO MDS3 & Passkey aaguid blobs (#17871) web: fix package-lock.json (#17809) website/integrations: oracle cloud: cleanup (#17808) website/integrations: Add Keycloak integration (#17813) website: bump the build group across 1 directory with 9 updates (#17849) lifecycle/aws: bump aws-cdk from 2.1031.0 to 2.1031.1 in /lifecycle/aws (#17850) core: bump astral-sh/uv from 0.9.6 to 0.9.7 (#17851) internal: full openssl path (#17856) outpost: revert breaking signals change (#17847) web/a11y: Isolated Outpost Error Page (#17683) provider/saml: make signing kp singleton (#17703) tasks: sanitize log attributes (#17833) ...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
currently
kidis always checked when using JWT federation even when no sources are configuredwhen federating with an OAuth2 provider only that has symmetric signing this fails
ref https://authentiksecurityinc.zendesk.com/agent/tickets/411