mirror of
https://github.com/pocket-id/pocket-id.git
synced 2026-10-02 15:59:04 +02:00
feat: support multiple client secrets per OIDC client (#1679)
This commit is contained in:
+28
@@ -0,0 +1,28 @@
|
||||
PRAGMA foreign_keys= OFF;
|
||||
BEGIN;
|
||||
|
||||
ALTER TABLE oidc_clients ADD COLUMN secret TEXT;
|
||||
|
||||
-- Only secrets that were migrated up from this same column can be restored, since the old column stores a bcrypt hash
|
||||
-- Secrets created while multiple secrets were supported are hashed with SHA-256 and are dropped here
|
||||
UPDATE oidc_clients
|
||||
SET secret = (
|
||||
SELECT json_extract(value, '$.hash')
|
||||
FROM json_each(json_extract(credentials, '$.secrets'))
|
||||
WHERE json_extract(value, '$.alg') = 'bcrypt'
|
||||
LIMIT 1
|
||||
)
|
||||
WHERE credentials IS NOT NULL
|
||||
AND credentials != ''
|
||||
AND json_valid(credentials)
|
||||
AND json_type(credentials, '$.secrets') = 'array';
|
||||
|
||||
UPDATE oidc_clients
|
||||
SET credentials = json_remove(credentials, '$.secrets')
|
||||
WHERE credentials IS NOT NULL
|
||||
AND credentials != ''
|
||||
AND json_valid(credentials)
|
||||
AND json_type(credentials, '$.secrets') = 'array';
|
||||
|
||||
COMMIT;
|
||||
PRAGMA foreign_keys= ON;
|
||||
+31
@@ -0,0 +1,31 @@
|
||||
PRAGMA foreign_keys= OFF;
|
||||
BEGIN;
|
||||
|
||||
-- Move the single client secret into the credentials document, as the only entry of the new "secrets" array
|
||||
-- Migrated secrets keep their bcrypt hash because the secret's value is not recoverable, and they never expire so that existing integrations keep working
|
||||
UPDATE oidc_clients
|
||||
SET credentials = json_set(
|
||||
COALESCE(NULLIF(credentials, ''), '{}'),
|
||||
'$.secrets',
|
||||
json_array(json_object(
|
||||
-- Generate a UUID
|
||||
'id', lower(
|
||||
hex(randomblob(4)) || '-' ||
|
||||
hex(randomblob(2)) || '-4' ||
|
||||
substr(hex(randomblob(2)), 2) || '-' ||
|
||||
substr('89ab', abs(random()) % 4 + 1, 1) || substr(hex(randomblob(2)), 2) || '-' ||
|
||||
hex(randomblob(6))
|
||||
),
|
||||
'alg', 'bcrypt',
|
||||
'hash', secret,
|
||||
'createdAt', strftime('%Y-%m-%dT%H:%M:%SZ', COALESCE(created_at, strftime('%s', 'now')), 'unixepoch')
|
||||
))
|
||||
)
|
||||
WHERE secret IS NOT NULL
|
||||
AND secret != ''
|
||||
AND (credentials IS NULL OR credentials = '' OR json_valid(credentials));
|
||||
|
||||
ALTER TABLE oidc_clients DROP COLUMN secret;
|
||||
|
||||
COMMIT;
|
||||
PRAGMA foreign_keys= ON;
|
||||
Reference in New Issue
Block a user