Meta tags:
description= Huly — All-in-One Project Management Platform (alternative to Linear, Jira, Slack, Notion, Motion) - fix(authProviders): defensive split for IdPs that put full name in given_name by MichaelUray · Pull Request #10919 · hcengineering/platform;
Headings (most frequently used words):
uh, oh, name, defensive, to, huly, 2026, saved, searches, fix, authproviders, split, for, idps, that, put, full, in, given_name, navigation, platform, michaeluray, feat, openid, footer, commented, jun, 21, github, staging, bot, loading, search, code, repositories, users, issues, pull, requests, provide, feedback, 10919, menu, use, filter, your, results, more, quickly, 10919michaeluray, wants, merge, commits, intohcengineering, develophcengineering, developfrom, splitmichaeluray, splitcopy, head, branch, clipboard, conversation, what, why, upstream, resolution, status, update, 06, 22, the, heuristic, tests, migration, note, out, of, scope, checklist, edited, by, there, was, an, error, while, please, reload, this, page, reviewers, assignees, labels, projects, milestone, development, participant,
Text of the page (most frequently used words):
name (28), the (27), this (23), #given_name (20), and (19), #github (17), that (16), split (14), authentik (14), for (13), family_name (13), code (12), michaeluray (12), heuristic (12), applied (11), security (10), all (10), huly (10), 2026 (9), merge (9), develop (9), platform (9), while (8), reload (8), default (8), preininger (8), authproviders (8), defensive (8), you (7), suggestion (7), cannot (7), suggestions (7), pull (7), from (7), was (7), signed (7), openid (7), full (7), conformant (7), with (7), fix (7), idps (7), can (6), not (6), please (6), loading (6), sign (6), open (6), oidc (6), scope (6), copy (6), shape (6), compound (6), hcengineering (6), your (6), enterprise (6), view (6), request (5), has (5), change (5), there (5), error (5), page (5), issues (5), off (5), michael (5), uray (5), users (5), into (5), feat (5), commits (5), mapping (5), non (5), names (5), florian (5), strict (5), whitespace (5), input (5), new (5), unchanged (5), user (5), search (5), community (4), navigation (4), add (4), single (4), commit (4), changes (4), when (4), branch (4), empty (4), com (4), upstream (4), display (4), first (4), use (4), fallback (4), legitimate (4), pods (4), src (4), any (4), quality (4), support (4), now (3), multi (3), line (3), batch (3), only (3), per (3), projects (3), account (3), conversation (3), hidden (3), characters (3), contains (3), unicode (3), review (3), format (3), noreply (3), 23231 (3), profile (3), jun (3), last (3), like (3), uses (3), missing (3), splitting (3), anna (3), lena (3), schmidt (3), oidcnamesplit (3), cases (3), idp (3), behaviour (3), same (3), 10919 (3), put (3), insights (3), actions (3), requests (3), settings (3), another (3), tab (3), window (3), refresh (3), session (3), saved (3), documentation (3), feedback (3), grade (3), features (3), copilot (3), solutions (3), explore (3), manage (2), status (2), footer (2), back (2), reviews (2), been (2), must (2), existing (2), create (2), one (2), closed (2), because (2), merging (2), may (2), development (2), milestone (2), none (2), yet (2), already (2), join (2), file (2), bidirectional (2), what (2), more (2), formatting (2), repo (2), fails (2), files (2), since (2), makes (2), tracking (2), auth (2), providers (2), core (2), goauthentik (2), sorry (2), something (2), went (2), wrong (2), reactions (2), markdown (2), link (2), commented (2), bot (2), staging (2), separation (2), verbatim (2), last_name (2), normalized (2), trim (2), otherwise (2), plan (2), would (2), mangle (2), logic (2), extracted (2), splitoidcname (2), claims (2), testability (2), test (2), cover (2), surname (2), space (2), dependencies (2), tests (2), other (2), out (2), before (2), update (2), first_name (2), similar (2), does (2), trigger (2), are (2), givenraw (2), custom (2), guard (2), full_name (2), will (2), maintainer (2), root (2), cause (2), ctx (2), state (2), issue (2), why (2), wants (2), head (2), clipboard (2), wiki (2), discussions (2), appearance (2), cancel (2), see (2), available (2), searches (2), repositories (2), business (2), advanced (2), developer (2), topics (2), source (2), resources (2), customer (2), services (2), devops (2), app (2), perform, action, time, share, personal, information, cookies, contact, docs, privacy, terms, inc, right, check, later, queued, comments, pending, marked, resolved, outdated, order, valid, applying, deleted, lines, supported, viewing, subset, invalid, were, made, participant, successfully, close, these, labels, assigned, assignees, reviewers, have, comment, free, show, text, interpreted, compiled, differently, than, appears, below, editor, reveals, learn, about, job, runs, step, drifted, base, committing, output, post, diff, again, functional, beyond, bc7264c, chore, apply, nsive, 143d840, remote, defe, added, july, callback, hardening, 10931, sets, referenced, connected, uberf, 16523, emits, previously, used, then, derived, producing, duplicated, blank, fall, codex, recommended, broad, pure, helper, candidate, benefits, also, quirk, gmail, 696f49d, breaking, api, unit, author, dco, each, checklist, touching, saml, provider, strategies, fixing, itself, affects, how, logins, populate, rows, retain, old, values, operators, wanting, backfill, run, happy, doc, snippet, helpful, global_account, person, migration, note, round, trip, identity, everything, crash, username, collapsed, padded, trimmed, degradation, applies, covers, explicitly, avoided, looser, where, happens, substring, triggers, google, microsoft, both, populated, correctly, familyraw, fullname, isauthentikdefaultshape, const, gated, fires, properly, configured, without, needing, removed, mis, configurations, keycloak, plugins, ops, produce, benefit, installations, admins, who, don, immediately, reconfigure, mappings, after, upgrade, still, affected, remains, valuable, defense, depth, confirmed, resolve, via, adding, separate, attributes, removing, need, correct, call, western, naming, conventions, falsehoods, article, family, 21544, v2026, dewi, tik, resolution, unanswered, 2024, trusts, blindly, hits, reported, against, onlyoffice, well, slice, undefined, stamped, ships, result, conformance, gap, detect, emit, violation, exact, detected, splits, instead, trusting, contributor, edited, changed, checks, additional, options, 789, 27k, star, fork, notification, notifications, public, message, dismiss, alert, switched, accounts, resetting, focus, qualifiers, our, query, filter, results, quickly, submit, include, email, address, contacted, read, every, piece, take, very, seriously, provide, syntax, tips, clear, jump, pricing, premium, ons, powered, collections, trending, archive, program, stars, accelerator, lab, programs, fund, developers, sponsors, partners, trust, center, forum, skills, ebooks, reports, events, webinars, stories, type, software, topic, industries, government, manufacturing, financial, healthcare, industry, devsecops, modernization, case, nonprofits, startups, small, medium, teams, enterprises, company, size, marketplace, changelog, blog, stop, leaks, they, start, secret, protection, secure, build, find, vulnerabilities, application, enforce, track, work, instant, dev, environments, codespaces, automate, workflow, workflows, integrate, external, tools, mcp, registry, direct, agents, write, better, creation, toggle, menu, skip, content,
Text of the page (random words):
fix authproviders defensive split for idps that put full name in given_name by michaeluray pull request 10919 hcengineering platform github skip to content navigation menu toggle navigation sign in appearance settings platform ai code creation github copilot write better code with ai github copilot app direct agents from issue to merge mcp registry new integrate external tools developer workflows actions automate any workflow codespaces instant dev environments issues plan and track work code review manage code changes code quality enforce quality at merge application security github advanced security find and fix vulnerabilities code security secure your code as you build secret protection stop leaks before they start explore why github documentation blog changelog marketplace view all features solutions by company size enterprises small and medium teams startups nonprofits by use case app modernization devsecops devops ci cd view all use cases by industry healthcare financial services manufacturing government view all industries view all solutions resources explore by topic ai software development devops security view all topics explore by type customer stories events webinars ebooks reports business insights github skills support services documentation customer support community forum trust center partners view all resources open source community github sponsors fund open source developers programs security lab maintainer community accelerator github stars archive program repositories topics trending collections enterprise enterprise solutions enterprise platform ai powered developer platform available add ons github advanced security enterprise grade security features copilot for business enterprise grade ai features premium support enterprise grade 24 7 support pricing search or jump to search code repositories users issues pull requests search clear search syntax tips provide feedback we read every piece of feedback and take your input very seriously include my email address so i can be contacted cancel submit feedback saved searches use saved searches to filter your results more quickly name query to see all available qualifiers see our documentation cancel create saved search sign in sign up appearance settings resetting focus you signed in with another tab or window reload to refresh your session you signed out in another tab or window reload to refresh your session you switched accounts on another tab or window reload to refresh your session dismiss alert message uh oh there was an error while loading please reload this page hcengineering platform public notifications you must be signed in to change notification settings fork 2k star 27k code issues 789 pull requests 66 discussions actions projects wiki security and quality 0 insights additional navigation options code issues pull requests discussions actions projects wiki security and quality insights fix authproviders defensive split for idps that put full name in given_name 10919 open michaeluray wants to merge 3 commits into hcengineering develop hcengineering platform develop from michaeluray feat openid defensive name split michaeluray huly platform feat openid defensive name split copy head branch name to clipboard conversation commits 3 3 checks files changed open fix authproviders defensive split for idps that put full name in given_name 10919 michaeluray wants to merge 3 commits into hcengineering develop hcengineering platform develop from michaeluray feat openid defensive name split michaeluray huly platform feat openid defensive name split copy head branch name to clipboard conversation michaeluray commented jun 21 2026 edited by huly github staging bot loading uh oh there was an error while loading please reload this page copy link copy markdown contributor what pods authproviders src openid ts now uses a strict normalized heuristic to detect idps that emit given_name full_name and family_name in violation of oidc core 1 0 5 1 when that exact shape is detected huly splits name on whitespace instead of trusting given_name verbatim otherwise behaviour is unchanged logic extracted into splitoidcname claims at pods authproviders src oidcnamesplit ts for testability why authentik s default oidc profile scope mapping ships with given_name request user name full display name and no family_name upstream issue tracking the conformance gap for users like florian preininger the result was ctx state user given_name florian preininger huly stamped first_name florian preininger ctx state user family_name undefined huly s fallback name split slice 1 join preininger account display florian preininger preininger the same root cause has been reported against onlyoffice as well unanswered since 2024 12 any rp that trusts given_name blindly and uses a split fallback for family_name hits this upstream resolution status update 2026 06 22 authentik s maintainer dewi tik in 23231 has confirmed the root cause and will resolve it in v2026 8 via pr 21544 adding separate first name family name user attributes removing the need for any name splitting heuristic at all this is the correct call splitting fails on non western naming conventions per the names falsehoods article this pr remains valuable as defense in depth authentik installations on 2026 8 and admins who don t immediately reconfigure scope mappings after upgrade are still affected other oidc providers with similar mis configurations keycloak plugins custom ops will produce the same shape and benefit from the same guard the heuristic is strict shape gated only fires when given_name full_name family_name so a properly configured authentik 2026 8 custom scope mapping makes this a no op without needing the guard to be removed the heuristic const isauthentikdefaultshape givenraw givenraw fullname familyraw conformant idps e g google github microsoft both given_name and family_name are populated correctly heuristic does not trigger behaviour unchanged legitimate compound names e g anna lena schmidt with given_name anna family_name lena schmidt family_name is non empty heuristic does not trigger authentik default similar non conformant idps heuristic triggers split on whitespace we explicitly avoided a looser given_name contains family_name heuristic because that would mangle legitimate compound names where family_name happens to be a substring of given_name tests pods authproviders src oidcnamesplit test ts covers 10 cases authentik default shape split applies conformant idp unchanged single name user with authentik shape no degradation legitimate compound surname unchanged compound first name unchanged whitespace padded input trimmed multi space input collapsed missing name fallback to username empty everything first last no crash round trip identity for already split conformant input migration note this change only affects how new logins populate first_name last_name on the huly account existing rows in global_account person from before this fix retain the old values operators wanting to backfill can run a strict heuristic update happy to add a doc snippet if helpful out of scope not fixing authentik s default mapping itself that s goauthentik authentik 23231 not touching the saml or other auth provider strategies no new dependencies checklist author dco sign off on each commit unit tests cover the new heuristic no behaviour change for conformant idps no new dependencies no breaking api change sorry something went wrong uh oh there was an error while loading please reload this page all reactions fix authproviders strict heuristic for authentik default given_name 696f49d shape authentik s default profile scope mapping has no first last separation and emits given_name full display name huly s openid ts previously used given_name verbatim then derived last_name from name split producing duplicated last names like florian preininger preininger now uses a strict normalized heuristic when given_name trim name trim and family_name is missing blank fall back to splitting full name on whitespace otherwise use given_name family_name as is per codex recommended plan review 2026 06 21 no broad given_name contains family_name fallback that would mangle legitimate compound names like anna lena schmidt logic extracted into pure helper splitoidcname claims at pods authproviders src oidcnamesplit ts for testability 10 test cases cover authentik default conformant idp single name compound surname whitespace missing name multi space and empty input upstream pr candidate this is a defensive fix that benefits any non authentik idp that also has the no separation quirk signed off by michael uray michael uray gmail com signed off by michael uray michaeluray users noreply github com huly github staging bot commented jun 21 2026 copy link copy markdown connected to huly uberf 16523 all reactions sorry something went wrong uh oh there was an error while loading please reload this page this was referenced jun 22 2026 default oidc profile scope mapping sets given_name to full display name non conformant with oidc core 1 0 5 1 goauthentik authentik 23231 closed auth providers oidc callback hardening 3 commits 10931 open michaeluray added 2 commits july 2 2026 06 13 merge remote tracking branch upstream develop into feat openid defe 143d840 nsive name split signed off by michael uray michaeluray users noreply github com chore merge develop and apply repo formatting bc7264c ci s formatting job runs the repo format step on the pr merge commit and fails when files drifted on develop since this branch s base merging develop and committing the format output makes the post format diff empty again no functional changes beyond the develop merge signed off by michael uray michaeluray users noreply github com this file contains hidden or bidirectional unicode text that may be interpreted or compiled differently than what appears below to review open the file in an editor that reveals hidden unicode characters learn more about bidirectional unicode characters show hidden characters sign up for free to join this conversation on github already have an account sign in to comment reviewers no reviews assignees no one assigned labels none yet projects none yet milestone no milestone development successfully merging this pull request may close these issues uh oh there was an error while loading please reload this page 1 participant add this suggestion to a batch that can be applied as a single commit this suggestion is invalid because no changes were made to the code suggestions cannot be applied while the pull request is closed suggestions cannot be applied while viewing a subset of changes only one suggestion per line can be applied in a batch add this suggestion to a batch that can be applied as a single commit applying suggestions on deleted lines is not supported you must change the existing code in this line in order to create a valid suggestion outdated suggestions cannot be applied this suggestion has been applied or marked resolved suggestions cannot be applied from pending reviews suggestions cannot be applied on multi line comments suggestions cannot be applied while the pull request is queued to merge suggestion cannot be applied right now please check back later footer 2026 github inc footer navigation terms privacy security status community docs contact manage cookies do not share my personal information you can t perform that action at this time
|