Add "resource" to LoginURL if defined. That helps to get 2FA
This commit is contained in:
parent
59adce3d63
commit
4f67c1acd4
|
|
@ -206,7 +206,11 @@ func (p *AzureProvider) GetLoginURL(redirectURI, state string) string {
|
||||||
params.Add("state", state)
|
params.Add("state", state)
|
||||||
params.Set("prompt", p.ApprovalPrompt)
|
params.Set("prompt", p.ApprovalPrompt)
|
||||||
params.Set("nonce", "FIXME")
|
params.Set("nonce", "FIXME")
|
||||||
|
if p.ProtectedResource != nil && p.ProtectedResource.String() != "" {
|
||||||
|
params.Add("resource", p.ProtectedResource.String())
|
||||||
|
}
|
||||||
a.RawQuery = params.Encode()
|
a.RawQuery = params.Encode()
|
||||||
|
|
||||||
return a.String()
|
return a.String()
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -351,3 +351,18 @@ func TestAzureRightPermittedGroups(t *testing.T) {
|
||||||
|
|
||||||
assert.Equal(t, true, result)
|
assert.Equal(t, true, result)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestAzureLoginURLnoResource(t *testing.T) {
|
||||||
|
p := testAzureProvider("")
|
||||||
|
p.ProtectedResource = nil
|
||||||
|
|
||||||
|
result := p.GetLoginURL("http://redirect/url", "state")
|
||||||
|
assert.Equal(t, "?client_id=&nonce=FIXME&prompt=&redirect_uri=http%3A%2F%2Fredirect%2Furl&response_mode=form_post&response_type=id_token+code&scope=openid&state=state", result)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAzureLoginURL(t *testing.T) {
|
||||||
|
p := testAzureProvider("")
|
||||||
|
|
||||||
|
result := p.GetLoginURL("http://redirect/url", "state")
|
||||||
|
assert.Equal(t, "?client_id=&nonce=FIXME&prompt=&redirect_uri=http%3A%2F%2Fredirect%2Furl&resource=https%3A%2F%2Fgraph.microsoft.com&response_mode=form_post&response_type=id_token+code&scope=openid&state=state", result)
|
||||||
|
}
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue