Fix OIDC email: load Authelia profile from UserInfo

Auth.js OIDC only reads ID-token claims by default; Authelia puts
email on UserInfo. Set idToken:false, harden claim extraction, and
document an optional Authelia claims_policy.
This commit is contained in:
Cursor Agent
2026-08-24 04:25:50 +00:00
parent c33f651cfe
commit 96c6df2fff
4 changed files with 83 additions and 16 deletions
+24
View File
@@ -0,0 +1,24 @@
import { describe, expect, it } from "vitest";
import { emailFromOidcProfile } from "@/lib/auth/oidc";
describe("emailFromOidcProfile", () => {
it("reads email claim", () => {
expect(emailFromOidcProfile({ email: "[email protected]" })).toBe(
"[email protected]"
);
});
it("falls back to preferred_username when it looks like an email", () => {
expect(
emailFromOidcProfile({ preferred_username: "[email protected]" })
).toBe("[email protected]");
});
it("ignores non-email preferred_username", () => {
expect(emailFromOidcProfile({ preferred_username: "nick" })).toBeNull();
});
it("returns null when nothing usable is present", () => {
expect(emailFromOidcProfile({ sub: "abc", name: "Nick" })).toBeNull();
});
});