mozilla-iam / auth0-deploy

Rules and hosted pages (lock) used for the Auth0 instances of Mozilla.
Mozilla Public License 2.0
7 stars 22 forks source link

set not only idToken.amr but also .oaud, .id #444

Closed floatingatoll closed 1 year ago

floatingatoll commented 1 year ago

Auth0 seems to be ignoring writes to the .amr field, so we've added two more copies of the group data to .oaud and .id and confirmed those are passed through to endpoints successfully.

floatingatoll commented 1 year ago

This change is already live in production as part of incident response; this PR resyncs the repo copy of this rule to match prod.