feat: add OIDC resource server scope prefix for Cognito compatibility

When OIDC_RESOURCE_SERVER_ID is set, prefix resource scopes with the
identifier when forwarding to the IdP (e.g., calendar.read becomes
https://example.com/calendar.read). Required for IdPs like AWS Cognito
that mandate {resource_server_id}/{scope} format for custom scopes.
OIDC standard scopes (openid, profile, email) are forwarded as-is.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Chris Coutinho
2026-04-07 16:33:47 +02:00
co-authored by Claude Opus 4.6
parent 2f146f8408
commit e21ddd91b9
3 changed files with 18 additions and 1 deletions
+1
View File
@@ -37,6 +37,7 @@ oidc_issuer = "@none"
jwks_uri = "@none"
introspection_uri = "@none"
userinfo_uri = "@none"
oidc_resource_server_id = "@none"
# --- Mode flags ---
enable_multi_user_basic_auth = false