mirror of
https://github.com/pocket-id/pocket-id.git
synced 2026-10-07 10:19:04 +02:00
feat: support multiple client secrets per OIDC client (#1679)
This commit is contained in:
+16
@@ -0,0 +1,16 @@
|
||||
ALTER TABLE oidc_clients ADD COLUMN secret TEXT;
|
||||
|
||||
-- Only secrets that were migrated up from this same column can be restored, since the old column stores a bcrypt hash
|
||||
-- Secrets created while multiple secrets were supported are hashed with SHA-256 and are dropped here
|
||||
UPDATE oidc_clients
|
||||
SET secret = (
|
||||
SELECT secret_entry ->> 'hash'
|
||||
FROM jsonb_array_elements(credentials -> 'secrets') AS secret_entry
|
||||
WHERE secret_entry ->> 'alg' = 'bcrypt'
|
||||
LIMIT 1
|
||||
)
|
||||
WHERE jsonb_typeof(credentials -> 'secrets') = 'array';
|
||||
|
||||
UPDATE oidc_clients
|
||||
SET credentials = credentials - 'secrets'
|
||||
WHERE jsonb_typeof(credentials -> 'secrets') = 'array';
|
||||
+14
@@ -0,0 +1,14 @@
|
||||
-- Move the single client secret into the credentials document, as the only entry of the new "secrets" array
|
||||
-- Migrated secrets keep their bcrypt hash because the secret's value is not recoverable, and they never expire so that existing integrations keep working
|
||||
UPDATE oidc_clients
|
||||
SET credentials = COALESCE(credentials, '{}'::jsonb) || jsonb_build_object(
|
||||
'secrets', jsonb_build_array(jsonb_build_object(
|
||||
'id', gen_random_uuid()::text,
|
||||
'alg', 'bcrypt',
|
||||
'hash', secret,
|
||||
'createdAt', to_char(COALESCE(created_at, now()) AT TIME ZONE 'UTC', 'YYYY-MM-DD"T"HH24:MI:SS"Z"')
|
||||
))
|
||||
)
|
||||
WHERE secret IS NOT NULL AND secret <> '';
|
||||
|
||||
ALTER TABLE oidc_clients DROP COLUMN secret;
|
||||
Reference in New Issue
Block a user