feat: support multiple client secrets per OIDC client (#1679)

This commit is contained in:
Alessandro (Ale) Segala
2026-08-11 00:54:52 +00:00
committed by GitHub
parent 03498e2f51
commit 155a1fcba0
29 changed files with 1353 additions and 165 deletions
@@ -0,0 +1,28 @@
PRAGMA foreign_keys= OFF;
BEGIN;
ALTER TABLE oidc_clients ADD COLUMN secret TEXT;
-- Only secrets that were migrated up from this same column can be restored, since the old column stores a bcrypt hash
-- Secrets created while multiple secrets were supported are hashed with SHA-256 and are dropped here
UPDATE oidc_clients
SET secret = (
SELECT json_extract(value, '$.hash')
FROM json_each(json_extract(credentials, '$.secrets'))
WHERE json_extract(value, '$.alg') = 'bcrypt'
LIMIT 1
)
WHERE credentials IS NOT NULL
AND credentials != ''
AND json_valid(credentials)
AND json_type(credentials, '$.secrets') = 'array';
UPDATE oidc_clients
SET credentials = json_remove(credentials, '$.secrets')
WHERE credentials IS NOT NULL
AND credentials != ''
AND json_valid(credentials)
AND json_type(credentials, '$.secrets') = 'array';
COMMIT;
PRAGMA foreign_keys= ON;
@@ -0,0 +1,31 @@
PRAGMA foreign_keys= OFF;
BEGIN;
-- Move the single client secret into the credentials document, as the only entry of the new "secrets" array
-- Migrated secrets keep their bcrypt hash because the secret's value is not recoverable, and they never expire so that existing integrations keep working
UPDATE oidc_clients
SET credentials = json_set(
COALESCE(NULLIF(credentials, ''), '{}'),
'$.secrets',
json_array(json_object(
-- Generate a UUID
'id', lower(
hex(randomblob(4)) || '-' ||
hex(randomblob(2)) || '-4' ||
substr(hex(randomblob(2)), 2) || '-' ||
substr('89ab', abs(random()) % 4 + 1, 1) || substr(hex(randomblob(2)), 2) || '-' ||
hex(randomblob(6))
),
'alg', 'bcrypt',
'hash', secret,
'createdAt', strftime('%Y-%m-%dT%H:%M:%SZ', COALESCE(created_at, strftime('%s', 'now')), 'unixepoch')
))
)
WHERE secret IS NOT NULL
AND secret != ''
AND (credentials IS NULL OR credentials = '' OR json_valid(credentials));
ALTER TABLE oidc_clients DROP COLUMN secret;
COMMIT;
PRAGMA foreign_keys= ON;