Repository navigation
Built against XNAT 1.10.1, Java 21.
New
- Optional claim-validation gates for token authorization — audience (
aud) and role — opt-in, and configurable once per provider or scoped to a single path. - Opt-in bearer-token authentication for REST requests carrying
Authorization: Bearer <jwt>. Tokens are fully validated: RSA signature against the provider's JWKS, plusissandexp. Note theaudgate is on by default on this path — setopenid.<providerId>.audCheck.acceptedAudiencesor every bearer token is rejected with 403 (fail-closed). - Opt-in account linking (
linkExisting.enabled) — on a mapping miss, attach the identity to the XNAT account another provider's mapping already names.linkExisting.sourceProvideris required; linking never creates accounts and grants nothing. - Opt-in auto-login (
autoLogin) via OIDCprompt=none, plus unified logout (logoutUri), which is meaningful only alongsideautoLogin. Only one provider may enable auto-login. usernamePatterncan now name a claim by URI, e.g.[https://example.org/upn]— for providers that namespace custom claims, Auth0 among them.
Fixed
- Account creation now refuses when a provider's
usernamePatternresolves to a login an XNAT account already holds and no mapping links the two. Previously the sign-in appeared to succeed while silently modifying the unrelated account. This changes behaviour for existing deployments with a collidingusernamePatternandforceUserCreateon: those logins used to go through and now fail, with the collision named in the log. ConfigurelinkExisting.sourceProviderto attach deliberately, or change the pattern so it stops colliding.
Full notes: CHANGELOG.md
Install: copy openid-auth-plugin-1.6.0-xpl.jar (the xpl classifier bundles the plugin's dependencies) into your XNAT plugins folder and restart.