fix: azure not providing email claim with custom tenant url #1399
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What kind of change does this PR introduce?
Bug fix
What is the current behavior?
The
email
claim is not returned when using a custom tenant URL, eg.https://login.microsoftonline.com/c2d53323-1e4f-4f73-ae1e-63ba1aff706b
This would result in an error like
Error getting user email from external provider
.Fixes #550, #292
What is the new behavior?
The email is now returned and auth is successful.
Additional context
After a whole bunch of debugging, turns out Azure just needed an explicit
email
scope to be included in the request.Edit: totally missed this somehow, but I think it makes more sense for this scope to always be requested rather than leaving that to the user.