Skip to content
Discussion options

You must be logged in to vote

So. Thanks you for reports:

there are two separate issues showed up in this thread.

First, after OAuth the UI lands on callback_url with a short-lived token in the query string. That value is not a JWT. The UI must call POST /api/v4/auth/oauth2/token with {"token":"..."} and use data.token as Authorization: Bearer .... Putting the query token directly in Authorization causes 401 on /me and dashboards.

Second, the coordinator only enables OAuth when coordinator.oauth2_provider is set up for the authorization code flow: client_id, auth_url, token_url, redirect_url, profile_url, and either client_secret (if use_pkce is false) or use_pkce true for a public client. A single pre-built url field…

Replies: 7 comments 7 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by adubovikov
Comment options

You must be logged in to vote
2 replies
@adubovikov
Comment options

@adubovikov
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@adubovikov
Comment options

Comment options

You must be logged in to vote
4 replies
@adubovikov
Comment options

@josh-hook
Comment options

@josh-hook
Comment options

@adubovikov
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants