AuzerAD: Handle empty `client_authentication` case (#99437)

AuzerAD: Require client secret when client_authentication is set to empty string
pull/99442/head
Karl Persson 12 months ago committed by GitHub
parent b0347792cc
commit b79f1b2a29
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
  1. 2
      pkg/login/social/connectors/azuread_oauth.go

@ -373,7 +373,7 @@ func validateClientAuthentication(info *social.OAuthInfo, requester identity.Req
}
return nil
case social.ClientSecretPost:
case social.ClientSecretPost, "":
if info.ClientSecret == "" {
return ssosettings.ErrInvalidOAuthConfig("Client secret is required for Client secret authentication.")
}

Loading…
Cancel
Save