Conversation
… DS bind methods The @reference to IdentityProviderConfig sat on a Map field, a type Declarative Services cannot inject, so SCR rejected it and bindIdentityProviderConfig was never called: /identityProviders stayed empty and no social auth module was generated. Move the annotation to the bind method, and do the same for AuthenticationService, whose bindIdentityProviderService (which registers the provider listener) was bypassed by field injection too. Also make getIdentityProviderByType return an empty list for a type with no bound provider, and add providers atomically. Fixes OpenIdentityPlatform#225
…d fix the social provider docs conf/identityProviders.json, the catalogue of supported social providers, was dropped from the distribution in 95c573c, so IdentityProviderService (ConfigurationPolicy.REQUIRE) never started and Configure > Social ID Providers offered nothing. Bring it back with current endpoints: Google's token and userinfo endpoints from its discovery document, Facebook's unversioned Graph endpoints without the discontinued locale field, and LinkedIn's OpenID Connect userinfo in place of the retired v1 API. The Integrator's Guide placed provider configuration in identityProviders.json. A provider is configured in its own identityProvider-<name>.json, which the Admin UI writes, SOCIAL_PROVIDERS reads and the configuration service encrypts client_secret in; identityProviders.json is only the catalogue. Fixes OpenIdentityPlatform#230
vharseko
force-pushed
the
issue-230-identity-provider-catalog
branch
from
September 30, 2026 09:20
d4dbb36 to
6dac993
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #230
Depends on #226. This branch carries #226's commit (
[#225] Bind identity provider configs through the DS bind methods) until #226 is merged; review only the[#230]commit here. With thecatalogue restored,
IdentityProviderServiceactivates on a stock install, and without #226 itsstart-up logs
SEVERE ... Field identityProviders ... has unsupported type java.util.Map(#225),which fails the start-up check of every
build-mavenjob. If #226 is squash-merged, this branch willbe rebased onto
masterto drop its copy of the commit.The problem
The Integrator's Guide (
chap-auth.adoc,appendix-auth-modules.adoc) says social identityproviders are configured in
conf/identityProviders.json. They are not:conf/identityProvider-<name>.json(PID
org.forgerock.openidm.identityProvider,IdentityProviderConfig.java:42-52); the Admin UIwrites it (
SocialConfigView.js:463,:475) andSOCIAL_PROVIDERSbuilds its modules from it(
AuthenticationService.java:413-417);conf/identityProviders.jsonconfigures the identity provider service itself; itsproviderslist is the catalogue returned by
availableProviders(IdentityProviderService.java:183-186,:277), which the Admin UI offers as templates withenabled: false(SocialConfigView.js:82-85);client_secretis encrypted only underorg.forgerock.openidm.identityProvider(
openidm-identity-provider/.../ConfigMeta.java:44-47), so a secret put where the guide saysstays in plain text.
On top of that the distribution ships no
identityProviders.jsonat all: it was removed in95c573c (OPENIDM-6689).
IdentityProviderServiceisConfigurationPolicy.REQUIRE, so on a stockinstall it never starts,
SocialDelegate.availableProviders()turns the 404 into{providers: []}, and Configure > Social ID Providers has nothing to offer.The change
conf/identityProviders.jsonis back, with the three providers the Admin UI has forms for(
google,facebook,linkedIn; the names are whatsetDisplayIconsand thesocial/_<name>.htmlpartials key on). The 2016 content is updated where the providers moved on:token_endpointanduserinfo_endpointfromaccounts.google.com/.well-known/openid-configuration;localemapping dropped, it is no longerin
claims_supported;so they do not expire the way
v2.3did); scopespublic_profile,email; the discontinuedlocalefield is no longer requested; the button usesfa fa-facebook, sinceimages/fb-logo.pngnever existed in this repository;r_basicprofileare gone; it now uses/v2/userinfowithopenid profile emailandauthenticationId: sub. It staysOAUTHrather thanOPENID_CONNECT: LinkedIn's id_tokeniss(https://www.linkedin.com) differs from theissuerin its discovery document (https://www.linkedin.com/oauth).conf/identityProvider-<name>.json(nametaken from the file name, written by the Admin UI,
client_secretstored encrypted), give a sampleidentityProvider-google.json, say that each generated module carries its provider'senabledflag, and describe
identityProviders.jsonas the catalogue that must stay in place.Default login is unchanged:
authentication.jsonhas noSOCIAL_PROVIDERSentry, and theidentityProvidersroute is readable byopenidm-authorizedonly (access.js:52-56). The catalogueholds no credentials.
Verification
On an
openidm-zip-7.1.1-SNAPSHOTdistribution (JDK 17) with thisconf/identityProviders.json:IdentityProviderServiceactivates;POST /openidm/identityProviders?_action=availableProvidersreturns
google,facebookandlinkedInwith the new endpoints and scopes;PUT /openidm/config/identityProvider/googlestoresclient_secretas$crypto, also in thewritten
conf/identityProvider-google.json;client_secretput intoconfig/identityProvidersis stored in plain text, as the docs now say;GET /openidm/identityProvidersstill answers{"providers":[]}with theSEVERE ... Field identityProviders ... has unsupported type java.util.Mapline — that is Configured identity providers are never bound, so /identityProviders is always empty #225, fixed by [#225] Bind identity provider configs through the DS bind methods #226, whosecommit this branch now carries (see above); this manual check was done before that rebase.
Not verified: a real login with any of the three providers (needs registered OAuth applications,
and #225 blocks it anyway), and whether LinkedIn echoes the
noncein its id_token, whichOAuthHttpClient.getProfilechecks when an id_token is present (OAuthHttpClient.java:161). TheAsciiDoc was not rendered; the new blocks follow the surrounding
+/[source, json]markup and thesocial-providers-moduleanchor exists.