Files
Apollo3zehnandApollo3zehn b0d87093a8 fix: propagate AdditionalClaims on session refresh (#3547)
AdditionalClaims were only extracted during the initial login. On
cookie refresh, buildSessionFromClaims did extract them into a new
session, but redeemRefreshToken only copied Email, User, Groups and
PreferredUsername back to the existing session, discarding the
AdditionalClaims.

This affects OIDC and MS Entra ID providers. Any header
injection relying on additional claims goes stale until the user
re-authenticates.

Signed-off-by: Apollo3zehn <Apollo3zehn@users.noreply.github.com>
Co-authored-by: Apollo3zehn <Apollo3zehn@users.noreply.github.com>
2026-09-30 17:40:17 +02:00
..
2025-11-16 22:38:59 +01:00
2024-03-04 01:42:00 +01:00
2025-08-12 17:41:45 +02:00
2022-10-21 11:57:51 +01:00
2025-08-19 08:40:36 +02:00
2024-01-22 13:39:53 +00:00
2024-01-22 13:39:53 +00:00
2022-10-21 11:57:51 +01:00
2024-03-04 01:42:00 +01:00
2024-01-22 13:39:53 +00:00