Skip to content

feat(oidc): Creation Of Azure Package For Resolving Group Overage Claims - #193

Merged
RyanDerr merged 1 commit into
llb-azure-entra-overage-supportfrom
rderr-azure-subpackage
Aug 31, 2026
Merged

RyanDerr merged 1 commit into
llb-azure-entra-overage-supportfrom
rderr-azure-subpackage

Conversation

@RyanDerr

@RyanDerr RyanDerr commented Aug 27, 2026 •

Copy link
Copy Markdown
Member

Overview

This PR adds a new oidc/azure package that aims to resolve Azure Entra ID distributed group claims. When a user belongs to more than 200 groups, Azure omits the groups claim from the token and replaces it with an overage indicator pointing to the Microsoft Graph API. This package exposes logic to detect when an overage is present in a token's claims, and fetch and return the full list of groups associated with the user when present.

Changes

  • Creation of a azure package which contains new function(s) ResolveGroupClaims and helper functions for detecting the overage indicator, resolving the correct regional Graph API endpoint, and fetching group IDs.
  • Addition of sentinel errors within the package to support input checks.
  • Package level doc explaining the overage scenario in Azure for groups, and providing official MSFT docs for when it's trigger and how to resolve them.

@RyanDerr RyanDerr self-assigned this Aug 27, 2026
Comment thread oidc/azure/azure.go
// Graph API using the provided OAuth2 token. When no overage indicator is
// present, it returns an empty map. On success, the returned map contains
// a "groups" key populated with the user's group IDs.
func ResolveGroupClaims(ctx context.Context, client *http.Client, token *oauth2.Token, claims map[string]any) (map[string]any, error) {

@RyanDerr RyanDerr Aug 27, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Open Question: Depending on how we want to treat the parent oidc lib to be more azure specific, wondering if should we return a map or just a slice of the group ids to persist and merge in the future with the claims from the resulting id token?

@RyanDerr
RyanDerr marked this pull request as ready for review August 27, 2026 17:34
@RyanDerr
RyanDerr requested a review from a team as a code owner August 27, 2026 17:34
@RyanDerr
RyanDerr changed the base branch from main to llb-azure-entra-overage-support August 27, 2026 17:38

@louisruch louisruch left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two nits but otherwise this looks great

Comment thread oidc/azure/azure.go Outdated
Comment thread oidc/azure/azure.go
@RyanDerr
RyanDerr requested a review from louisruch August 27, 2026 21:37
@RyanDerr
RyanDerr force-pushed the rderr-azure-subpackage branch from 8fa27cf to da6065e Compare August 31, 2026 13:34
…distrubuted overage claims provided by Azure from returned OIDC exchanged claims
@RyanDerr
RyanDerr force-pushed the rderr-azure-subpackage branch from da6065e to 598dd87 Compare August 31, 2026 15:08
@RyanDerr
RyanDerr merged commit 598dd87 into llb-azure-entra-overage-support Aug 31, 2026
2 checks passed
@RyanDerr
RyanDerr deleted the rderr-azure-subpackage branch August 31, 2026 15:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants