From e0345512d9fe8b255334d4260eda4454248d82dd Mon Sep 17 00:00:00 2001 From: Xavier Morel Date: Mon, 16 May 2022 09:07:30 +0000 Subject: [PATCH] [FIX] auth_oauth: google rejects nonce if response_type=token I apparently missed this case in #88871: Google's legacy flow (response_type=token) explicitly rejects a `nonce` parameter being passed in the authentication request. The nonce parameter is only accepted for an OIDC-conformant implicit flow request (aka `response_type=token id_token`). The specific endpoint doesn't seem to have any bearing on this, v1 and v2 authentication endpoints result in the same behavior. Drawback: Okta isn't supported anymore, as it requires the nonce, no if, no but, even on "legacy" auth requests, possibly others. However since these already weren't supported that's considered less of an issue than possibly breaking compatibility with existing IDP. Rejected alternative: adding `id_token` to the `response_type` to come closer to OIDC-conformant request, however that was considered too risky: Odoo clients could be using legacy IDP which also reject the nonce parameter but don't have a magic "OIDC conformant" trigger. closes odoo/odoo#91500 X-original-commit: 1fd738d9826f9bdfe8deddd5ef81dcb9757e8988 Signed-off-by: Xavier Morel (xmo) Signed-off-by: Olivier Dony --- addons/auth_oauth/controllers/main.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/auth_oauth/controllers/main.py b/addons/auth_oauth/controllers/main.py index 799618d34ef..2890384cba9 100644 --- a/addons/auth_oauth/controllers/main.py +++ b/addons/auth_oauth/controllers/main.py @@ -65,7 +65,7 @@ class OAuthLogin(Home): redirect_uri=return_url, scope=provider['scope'], state=json.dumps(state), - nonce=base64.urlsafe_b64encode(os.urandom(16)), + # nonce=base64.urlsafe_b64encode(os.urandom(16)), ) provider['auth_link'] = "%s?%s" % (provider['auth_endpoint'], werkzeug.urls.url_encode(params)) return providers