Skip to content

fix: remove token claims from userinfo - #982

Merged
Goosetaf merged 1 commit into
mainfrom
fix/userinfo-leak
Sep 29, 2026
Merged

Goosetaf merged 1 commit into
mainfrom
fix/userinfo-leak

Conversation

@Goosetaf

Copy link
Copy Markdown
Member

This PR resolves a problem in SyncIT when logging in, as .NET's JwtPayload.Deserialize enforces types for nbf/exp/iat in any JSON object. This only became an issue after Spring Security started serializing nbf as a string.

As stated in OIDC Core §5.3, the endpoint should return the claims about the user. Therefore, also including token claims creates a spec misalignment.

@Goosetaf
Goosetaf requested review from Portals and a balanced review from Copilot September 28, 2026 08:12

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@audiotrope

Copy link
Copy Markdown

🔥

@Goosetaf
Goosetaf merged commit dcf2e5c into main Sep 29, 2026
2 checks passed
@Goosetaf
Goosetaf deleted the fix/userinfo-leak branch September 29, 2026 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants