Log why the OIDC callback refused an exchanged code #214
Loading…
Reference in a new issue
No description provided.
Delete branch "log-oidc-exchange-failure"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
A real sign-in against Authentik got a 200 from the token endpoint and then a 401 from the callback, with nothing in the log saying why. The catch in
GetCallbackswallowed theOidcExchangeFailedExceptionwhose message and inner exception carry the reason. This logs it at Warning under the endpoint's own category before rethrowing the deliberately blank 401. The response is unchanged.Tested with a new
OidcEndpointsTestscase that drives the refused-code branch and asserts the record. Watched it fail with the log call removed. Full suite green on SDK 10.0.100.Verdict: mergeable
Nothing to change. The catch still throws
OidcFlowInvalidException, so the 401 and its body are unchanged (the existing identical-refusal test covers that). EveryOidcExchangeFailedExceptionmessage inOidcProviderClientis a fixed string naming the step; none carries the code, token, verifier or secret, andShowPIIis not enabled anywhere, so the validator's inner exception stays redacted. The log follows the_logCategory+ILoggerFactoryshape inAuthenticationEndpoints. Deleting the two log lines from the catch turns the new test red onShouldHaveSingleItem.