User signup Custom Attribute and External IDP claim mapping - #105
Merged
Merged
Conversation
release changes | 2.2
🔍 EOL Dependencies Check Results🔍 Dependencies End-of-Life ReportGenerated on 2026-09-17 02:51:22 UTC 📊 Summary
✅ Supported DependenciesClick to expand untracked dependencies
❓ Untracked DependenciesClick to expand untracked dependenciesThese dependencies could not be tracked, as they were not found in the EOL database:
🔧 RecommendationsUseful Resources
|
🧪 Maven Test Results📊 Test Report SummaryTest Results Overview
Module Test Breakdown
This summary was generated by the Maven Test Workflow for Pull Request #105 |
Sonar issue fixes
🔍 EOL Dependencies Check Results🔍 Dependencies End-of-Life ReportGenerated on 2026-09-17 13:46:11 UTC 📊 Summary
✅ Supported DependenciesClick to expand untracked dependencies
❓ Untracked DependenciesClick to expand untracked dependenciesThese dependencies could not be tracked, as they were not found in the EOL database:
🔧 RecommendationsUseful Resources
|
🧪 Maven Test Results📊 Test Report SummaryTest Results Overview
Module Test Breakdown
This summary was generated by the Maven Test Workflow for Pull Request #105 |
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Please refer to our contributing docs for any questions on submitting a pull request.
Issues are required for both bug fixes and features.
Resolves #ISSUE_NUMBER
Describe behaviour before the change
user_attributes) had no way to define a human-readableattributeLabelfor signup UI display; only static field names were shown.FIELD_NAME_REGEX) and could not include reserved/mandatory field names such asphoneNumber, causing collisions to go undetected until runtime.GET /users/attributesreturned all metadata with no way to filter by static vs. dynamic (custom) attributes.ApplicationRuntimeException, losing the original field name(s) reported to the client.getUserDefaultAccountName()), with no way for an external IDP/client to override it per sign-up request.updatedBy/updateDate) were inconsistently set (or leftnull) when creating accounts, roles, scopes, users, and client registrations.stringToTime/stringToTimestamponly supported strict SQL formats and threw exceptions on the shorter ISO formats sent by HTML<input type="time">/<input type="datetime-local">fields.LocalDateTime/ZonedDateTimeconversions with system default time zone, and a JDBCConnectionobtained from a tenant datasource was not being closed.Describe behaviour after the change
attribute_labelcolumn touser_attributes(via Liquibase changeset2_2_release/user_attributes_data.xml) and correspondingattributeLabelfield onUserAttributeEntity,UserMetaDataRequest, andUserMetaDataResponse, with@AssertTruevalidation requiring a label when the attribute is static (dynamicAttribute=false).GET /users/attributes?dynamicAttribute=true|falsesupport viaUsersService#getSignupAttributesandUserAttributeRepository#findByDynamicAttribute, allowing callers to filter attribute metadata for the signup UI.ATTRIBUTE_NAME_RESERVED) that rejects new custom attributes whose name collides with a mandatory/core user field.@Patternregex on attribute names inUserMetaDataRequest; reducedMAX_FIELD_NAME_LENGTHfrom 79 to 50, and added support for names likecustom:companyName.DANGEROUS_INPUT_PATTERN-based validation (isAttributeValueSafe) inUsersServiceImplto reject additional-attribute values containing HTML/script tags,javascript:URIs, event handlers, or SQL-injection patterns; unknown attribute keys are now skipped (logged as a warning) instead of throwing, and regex validation fromUserAttributeEntity#getRegexis now applied across all data types (not just String).ApplicationRuntimeExceptions thrown during additional-attribute validation inselfAddUserare now rethrown as-is instead of being re-wrapped, preserving the original field name(s) in the responseparameters.signupDefaultAccountadditional attribute;mapToAccountsAndRolesnow prefers this value over the tenant-level default account name when present.updatedBy/updateDate(orcreateDate) onAccountEntity,RolesEntity,ScopesEntity,ClientEntity, andUserEntityduring create/update/delete flows acrossAccountServiceImpl,RolesService,ScopesService,ClientRegistrationServiceImpl, andUsersServiceImpl.ObjectConverter.stringToTime/stringToTimestampnow accept shortHH:mmtime and multiple ISO 8601 datetime formats (yyyy-MM-ddTHH:mm,yyyy-MM-ddTHH:mm:ss, offset, and instant formats), returningnullfor blank input instead of throwing.LocalDateTime/ZonedDateTime-based lock/unlock calculations withInstant-based calculations to avoid timezone-dependent bugs; fixed a resource leak by using try-with-resources for the tenant JDBCConnectioninLiquibaseConfig.UsersServiceImplnow uses constructor injection (@RequiredArgsConstructor) with explicit@Autowiredfield annotations instead of@AllArgsConstructor, andgetUserByUserName/attribute-population logic now merges custom attribute values (user_attribute_values) into the response.UsersServiceAddUserStatusTest(user status preservation logic),InputSanitizerTest,BodyInserterWrapperTest, additional cases inUsersServiceTest,UsersServiceLockUnlockTest,ObjectConverterTest, andUserAttributeSpecificationTest(migrated fromIntegertoBigIntegerattribute IDs).Pull request checklist
Does this introduce a breaking change?