fix: enhance auth_callback to support client authentication via POST body for OIDC providers
This commit is contained in:
@@ -89,6 +89,13 @@ async def auth_callback(payload: AuthCallbackRequest):
|
||||
async with httpx.AsyncClient(timeout=15.0) as client:
|
||||
response = await client.post(token_endpoint, data=data, headers={"Accept": "application/json"}, auth=auth)
|
||||
|
||||
# Some providers only accept client authentication via POST body
|
||||
if response.status_code != 200 and auth is not None:
|
||||
# try falling back to client_secret in the request body
|
||||
data_with_secret = dict(data)
|
||||
data_with_secret["client_secret"] = settings.oidc_client_secret
|
||||
response = await client.post(token_endpoint, data=data_with_secret, headers={"Accept": "application/json"})
|
||||
|
||||
if response.status_code != 200:
|
||||
raise HTTPException(status_code=400, detail=f"OIDC token exchange failed: {response.text}")
|
||||
|
||||
|
||||
Reference in New Issue
Block a user