Spaces:
				
			
			
	
			
			
					
		Running
		
	
	
	
			
			
	
	
	
	
		
		
					
		Running
		
	Make compatible with Microsoft Entra (v1 and v2 tokens) (#821)
Browse files* Make the profile picture claim optional
Some identity providers (such as Azure AD) do not provide or support the
picture claim. This patch makes it optional.
* Allow using Microsoft Entra v1 tokens
---------
Co-authored-by: Nathan Sarrazin <[email protected]>
    	
        src/lib/types/User.ts
    CHANGED
    
    | @@ -7,6 +7,6 @@ export interface User extends Timestamps { | |
| 7 | 
             
            	username?: string;
         | 
| 8 | 
             
            	name: string;
         | 
| 9 | 
             
            	email?: string;
         | 
| 10 | 
            -
            	avatarUrl: string;
         | 
| 11 | 
             
            	hfUserId: string;
         | 
| 12 | 
             
            }
         | 
|  | |
| 7 | 
             
            	username?: string;
         | 
| 8 | 
             
            	name: string;
         | 
| 9 | 
             
            	email?: string;
         | 
| 10 | 
            +
            	avatarUrl: string | undefined;
         | 
| 11 | 
             
            	hfUserId: string;
         | 
| 12 | 
             
            }
         | 
    	
        src/routes/login/callback/updateUser.ts
    CHANGED
    
    | @@ -18,6 +18,12 @@ export async function updateUser(params: { | |
| 18 | 
             
            }) {
         | 
| 19 | 
             
            	const { userData, locals, cookies, userAgent, ip } = params;
         | 
| 20 |  | 
|  | |
|  | |
|  | |
|  | |
|  | |
|  | |
| 21 | 
             
            	const {
         | 
| 22 | 
             
            		preferred_username: username,
         | 
| 23 | 
             
            		name,
         | 
| @@ -28,7 +34,7 @@ export async function updateUser(params: { | |
| 28 | 
             
            		.object({
         | 
| 29 | 
             
            			preferred_username: z.string().optional(),
         | 
| 30 | 
             
            			name: z.string(),
         | 
| 31 | 
            -
            			picture: z.string(),
         | 
| 32 | 
             
            			sub: z.string(),
         | 
| 33 | 
             
            			email: z.string().email().optional(),
         | 
| 34 | 
             
            		})
         | 
|  | |
| 18 | 
             
            }) {
         | 
| 19 | 
             
            	const { userData, locals, cookies, userAgent, ip } = params;
         | 
| 20 |  | 
| 21 | 
            +
            	// Microsoft Entra v1 tokens do not provide preferred_username, instead the username is provided in the upn
         | 
| 22 | 
            +
            	// claim. See https://learn.microsoft.com/en-us/entra/identity-platform/access-token-claims-reference
         | 
| 23 | 
            +
            	if (!userData.preferred_username && userData.upn) {
         | 
| 24 | 
            +
            		userData.preferred_username = userData.upn as string;
         | 
| 25 | 
            +
            	}
         | 
| 26 | 
            +
             | 
| 27 | 
             
            	const {
         | 
| 28 | 
             
            		preferred_username: username,
         | 
| 29 | 
             
            		name,
         | 
|  | |
| 34 | 
             
            		.object({
         | 
| 35 | 
             
            			preferred_username: z.string().optional(),
         | 
| 36 | 
             
            			name: z.string(),
         | 
| 37 | 
            +
            			picture: z.string().optional(),
         | 
| 38 | 
             
            			sub: z.string(),
         | 
| 39 | 
             
            			email: z.string().email().optional(),
         | 
| 40 | 
             
            		})
         | 

