mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-09-30 19:51:22 +02:00
AdditionalClaims were only extracted during the initial login. On cookie refresh, buildSessionFromClaims did extract them into a new session, but redeemRefreshToken only copied Email, User, Groups and PreferredUsername back to the existing session, discarding the AdditionalClaims. This affects OIDC and MS Entra ID providers. Any header injection relying on additional claims goes stale until the user re-authenticates. Signed-off-by: Apollo3zehn <Apollo3zehn@users.noreply.github.com> Co-authored-by: Apollo3zehn <Apollo3zehn@users.noreply.github.com>