feat: support multiple client secrets per OIDC client (#1679)

This commit is contained in:
Alessandro (Ale) Segala
2026-08-11 00:54:52 +00:00
committed by GitHub
parent 03498e2f51
commit 155a1fcba0
29 changed files with 1353 additions and 165 deletions
@@ -0,0 +1,16 @@
ALTER TABLE oidc_clients ADD COLUMN secret TEXT;
-- Only secrets that were migrated up from this same column can be restored, since the old column stores a bcrypt hash
-- Secrets created while multiple secrets were supported are hashed with SHA-256 and are dropped here
UPDATE oidc_clients
SET secret = (
SELECT secret_entry ->> 'hash'
FROM jsonb_array_elements(credentials -> 'secrets') AS secret_entry
WHERE secret_entry ->> 'alg' = 'bcrypt'
LIMIT 1
)
WHERE jsonb_typeof(credentials -> 'secrets') = 'array';
UPDATE oidc_clients
SET credentials = credentials - 'secrets'
WHERE jsonb_typeof(credentials -> 'secrets') = 'array';
@@ -0,0 +1,14 @@
-- Move the single client secret into the credentials document, as the only entry of the new "secrets" array
-- Migrated secrets keep their bcrypt hash because the secret's value is not recoverable, and they never expire so that existing integrations keep working
UPDATE oidc_clients
SET credentials = COALESCE(credentials, '{}'::jsonb) || jsonb_build_object(
'secrets', jsonb_build_array(jsonb_build_object(
'id', gen_random_uuid()::text,
'alg', 'bcrypt',
'hash', secret,
'createdAt', to_char(COALESCE(created_at, now()) AT TIME ZONE 'UTC', 'YYYY-MM-DD"T"HH24:MI:SS"Z"')
))
)
WHERE secret IS NOT NULL AND secret <> '';
ALTER TABLE oidc_clients DROP COLUMN secret;