feat(oidc): Creation Of Azure Package For Resolving Group Overage Claims - #193
Merged
Merged
Conversation
RyanDerr
commented
Aug 27, 2026
| // Graph API using the provided OAuth2 token. When no overage indicator is | ||
| // present, it returns an empty map. On success, the returned map contains | ||
| // a "groups" key populated with the user's group IDs. | ||
| func ResolveGroupClaims(ctx context.Context, client *http.Client, token *oauth2.Token, claims map[string]any) (map[string]any, error) { |
Member
Author
There was a problem hiding this comment.
Open Question: Depending on how we want to treat the parent oidc lib to be more azure specific, wondering if should we return a map or just a slice of the group ids to persist and merge in the future with the claims from the resulting id token?
louisruch
reviewed
Aug 27, 2026
louisruch
left a comment
Collaborator
There was a problem hiding this comment.
Two nits but otherwise this looks great
louisruch
approved these changes
Aug 28, 2026
RyanDerr
force-pushed
the
rderr-azure-subpackage
branch
from
August 31, 2026 13:34
8fa27cf to
da6065e
Compare
bgajjala8
approved these changes
Aug 31, 2026
…distrubuted overage claims provided by Azure from returned OIDC exchanged claims
RyanDerr
force-pushed
the
rderr-azure-subpackage
branch
from
August 31, 2026 15:08
da6065e to
598dd87
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
This PR adds a new
oidc/azurepackage that aims to resolve Azure Entra ID distributed group claims. When a user belongs to more than 200 groups, Azure omits the groups claim from the token and replaces it with an overage indicator pointing to the Microsoft Graph API. This package exposes logic to detect when an overage is present in a token's claims, and fetch and return the full list of groups associated with the user when present.Changes
azurepackage which contains new function(s)ResolveGroupClaimsand helper functions for detecting the overage indicator, resolving the correct regional Graph API endpoint, and fetching group IDs.