kubeguard / guard

🔑 Kubernetes Authentication & Authorization WebHook Server
https://kubeguard.dev
Apache License 2.0
590 stars 81 forks source link

Fix idtyp issue with GetMemberGroupsUsingARCOboService #392

Closed vineeth-thumma closed 3 months ago

vineeth-thumma commented 3 months ago

For more context, "idtyp" claim is used to get the type of token (app, user, device). By default, it's only emitted for app-only tokens (which seems to have changed now) Like all optional claims that affect the access token, the resource in the request must set this optional claim, since resources own the access token https://learn.microsoft.com/en-us/entra/identity-platform/optional-claims-reference#additionalproperties-of-optional-claims