Huge News!Announcing our $40M Series B led by Abstract Ventures.Learn More
Socket
Sign inDemoInstall
Socket

@mongodb-js/oidc-plugin

Package Overview
Dependencies
Maintainers
33
Versions
26
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@mongodb-js/oidc-plugin - npm Package Compare versions

Comparing version 0.3.0 to 0.3.1

3

dist/log-hook.js

@@ -110,4 +110,7 @@ "use strict";

});
emitter.on('mongodb-oidc-plugin:missing-id-token', () => {
log.warn('OIDC-PLUGIN', mongoLogId(1002000022), `${contextPrefix}-oidc`, 'Missing ID token in IdP response');
});
}
exports.hookLoggerToMongoLogWriter = hookLoggerToMongoLogWriter;
//# sourceMappingURL=log-hook.js.map

44

dist/plugin.js

@@ -325,19 +325,35 @@ "use strict";

// receive mismatching tokens for different users or different audiences.
const idTokenClaims = tokenSet.claims();
if (state.lastIdTokenClaims) {
for (const claim of ['aud', 'sub']) {
const normalize = (value) => {
return JSON.stringify(Array.isArray(value) ? [...value].sort() : value);
};
const knownClaim = normalize(state.lastIdTokenClaims[claim]);
const newClaim = normalize(idTokenClaims[claim]);
if (knownClaim !== newClaim) {
throw new types_1.MongoDBOIDCError(`Unexpected '${claim}' field in id token: Expected ${knownClaim}, saw ${newClaim}`);
if (!tokenSet.id_token &&
state.lastIdTokenClaims &&
!state.lastIdTokenClaims.noIdToken) {
throw new types_1.MongoDBOIDCError(`ID token expected, but not found. Expected claims: ${JSON.stringify(state.lastIdTokenClaims)}`);
}
if (tokenSet.id_token &&
state.lastIdTokenClaims &&
state.lastIdTokenClaims.noIdToken) {
throw new types_1.MongoDBOIDCError(`Unexpected ID token received.`);
}
if (tokenSet.id_token) {
const idTokenClaims = tokenSet.claims();
if (state.lastIdTokenClaims && !state.lastIdTokenClaims.noIdToken) {
for (const claim of ['aud', 'sub']) {
const normalize = (value) => {
return JSON.stringify(Array.isArray(value) ? [...value].sort() : value);
};
const knownClaim = normalize(state.lastIdTokenClaims[claim]);
const newClaim = normalize(idTokenClaims[claim]);
if (knownClaim !== newClaim) {
throw new types_1.MongoDBOIDCError(`Unexpected '${claim}' field in id token: Expected ${knownClaim}, saw ${newClaim}`);
}
}
}
state.lastIdTokenClaims = {
aud: idTokenClaims.aud,
sub: idTokenClaims.sub,
};
}
state.lastIdTokenClaims = {
aud: idTokenClaims.aud,
sub: idTokenClaims.sub,
};
else {
state.lastIdTokenClaims = { noIdToken: true };
this.logger.emit('mongodb-oidc-plugin:missing-id-token');
}
const timerDuration = automaticRefreshTimeoutMS(tokenSet);

@@ -344,0 +360,0 @@ // Use `.call()` because in browsers, `setTimeout()` requires that it is called

@@ -65,2 +65,3 @@ /** @public */

'mongodb-oidc-plugin:destroyed': () => void;
'mongodb-oidc-plugin:missing-id-token': () => void;
}

@@ -67,0 +68,0 @@ /** @public */

@@ -143,2 +143,3 @@ /// <reference types="node" />

'mongodb-oidc-plugin:destroyed': () => void;
'mongodb-oidc-plugin:missing-id-token': () => void;
}

@@ -145,0 +146,0 @@

@@ -16,3 +16,3 @@ {

"homepage": "https://github.com/mongodb-js/oidc-plugin",
"version": "0.3.0",
"version": "0.3.1",
"repository": {

@@ -61,3 +61,3 @@ "type": "git",

"@mongodb-js/monorepo-tools": "^1.1.4",
"@mongodb-js/oidc-mock-provider": "^0.6.2",
"@mongodb-js/oidc-mock-provider": "^0.7.1",
"@mongodb-js/prettier-config-devtools": "^1.0.1",

@@ -67,3 +67,3 @@ "@mongodb-js/tsconfig-devtools": "^1.0.0",

"@types/express": "^4.17.17",
"@types/mocha": "^9.0.0",
"@types/mocha": "^10.0.2",
"@types/node": "^18.13.0",

@@ -74,3 +74,3 @@ "@types/oidc-provider": "^8.1.1",

"depcheck": "^1.4.1",
"electron": "^23.1.2",
"electron": "^26.2.0",
"electron-mocha": "^12.0.0",

@@ -77,0 +77,0 @@ "eslint": "^7.25.0",

Sorry, the diff of this file is not supported yet

Sorry, the diff of this file is not supported yet

Sorry, the diff of this file is not supported yet

Sorry, the diff of this file is not supported yet

Sorry, the diff of this file is not supported yet

Sorry, the diff of this file is not supported yet

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc