You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: obp-api/src/main/scripts/sql/create_oidc_user_and_views.sql
+59-17Lines changed: 59 additions & 17 deletions
Original file line number
Diff line number
Diff line change
@@ -77,12 +77,12 @@ ALTER USER :OIDC_USER CONNECTION LIMIT 10;
77
77
\echo 'Creating read-only view for OIDC access to authuser...'
78
78
79
79
-- Drop the view if it already exists
80
-
DROPVIEW IF EXISTS v_authuser_oidc CASCADE;
80
+
DROPVIEW IF EXISTS v_oidc_users CASCADE;
81
81
82
82
-- Create a read-only view exposing only necessary authuser fields for OIDC
83
83
-- TODO: Consider excluding locked users by joining with mappedbadloginattempt table
84
84
-- and checking mbadattemptssinceresetorsuccess against max.bad.login.attempts prop
85
-
CREATEVIEWv_authuser_oidcAS
85
+
CREATEVIEWv_oidc_usersAS
86
86
SELECT
87
87
id,
88
88
username,
@@ -101,9 +101,38 @@ WHERE validated = true -- Only expose validated users to OIDC service
101
101
ORDER BY username;
102
102
103
103
-- Add comment to the view for documentation
104
-
COMMENT ON VIEW v_authuser_oidc IS 'Read-only view of authuser table for OIDC service access. Only includes validated users. WARNING: Includes password hash and salt for OIDC credential verification - ensure secure access.';
104
+
COMMENT ON VIEW v_oidc_users IS 'Read-only view of authuser table for OIDC service access. Only includes validated users and excludes sensitive fields like password hashes. WARNING: Includes password hash and salt for OIDC credential verification - ensure secure access.';
WHERE isactive = true -- Only expose active consumers to OIDC service
130
+
ORDER BY client_name;
131
+
132
+
-- Add comment to the view for documentation
133
+
COMMENT ON VIEW v_oidc_clients IS 'Read-only view of consumer table for OIDC service access. Only includes active consumers. Note: grant_types and scopes are hardcoded defaults - consider adding these fields to consumer table for full OIDC compliance.';
0 commit comments