You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit b2edc4f
Browse filesBrowse the repository at this point in the historyBrowse files
`Strategy ${strategy.id} named ${unmatched.length} group(s) this wiki does not have, for user ${userId}: ${unmatched.join(', ')}`
925
-
)
926
-
}
922
+
/*
923
+
Both halves of the answer, and logged even when the provider named nothing: an empty claim is
924
+
the commonest reason a group mapping appears not to work, and it is silent everywhere else — the
925
+
wanted set below then simply equals the current one. What the provider said about this person is
926
+
logged by the module; this is what the wiki could do with it.
927
+
*/
928
+
WIKI.models.flags.authDebug(
929
+
`Strategy ${strategy.id} named ${profile.groups.length} group(s) for user ${userId}: ${matched.length} matched a wiki group (${matched.map((grp)=>grp.name).join(', ')||'none'})${unmatched.length>0 ? `, ${unmatched.length} did not (${unmatched.join(', ')})` : ''}`
`${account.username} (${account.id}) signs in as <${account.email}>${groups ? `, holding ${groups.length} mapped role(s): ${groups.join(', ')||'none'}` : ', groups not mapped'}`
334
+
)
335
+
293
336
return{
294
337
id: String(account.id),
295
338
email: account.email,
296
339
// -> `global_name` is the display name; `username` is the handle, and is all an account that
`has \`${tenantId}\` as its Directory (tenant) ID, which is a multi-tenant placeholder — this module needs the tenant's own ID, since it accepts tokens from that directory alone (see MULTI_TENANT)`
The single most common way an Entra strategy does not work, which is why the log says what to
151
+
do about it: `email` is only emitted for an account with a Mail attribute or a tenant that
152
+
maps the optional claim, and `preferred_username` is where the address is otherwise.
153
+
*/
154
+
strategyDebug(
155
+
this,
156
+
`the \`${emailClaim}\` claim carries no address — set Email Claim to \`preferred_username\`, or map the \`email\` optional claim on the app registration`
0 commit comments