diff --git a/backend/src/services/identity-oidc-auth/identity-oidc-auth-service.ts b/backend/src/services/identity-oidc-auth/identity-oidc-auth-service.ts index e94b7f823..7245278bf 100644 --- a/backend/src/services/identity-oidc-auth/identity-oidc-auth-service.ts +++ b/backend/src/services/identity-oidc-auth/identity-oidc-auth-service.ts @@ -23,6 +23,7 @@ import { UnauthorizedError } from "@app/lib/errors"; import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip"; +import { logger } from "@app/lib/logger"; import { AuthAttemptAuthMethod, AuthAttemptAuthResult, authAttemptCounter } from "@app/lib/telemetry/metrics"; import { getValueByDot } from "@app/lib/template/dot-access"; @@ -145,6 +146,10 @@ export const identityOidcAuthServiceFactory = ({ } } else { // If kid is not provided, try all available signing keys + logger.warn( + `OIDC login without KID header [identityId=${identityOidcAuth.identityId}] [orgId=${org.id}] [ip=${requestContext.get("ip")}]` + ); + let allSigningKeys; try { allSigningKeys = await client.getSigningKeys(); @@ -160,6 +165,14 @@ export const identityOidcAuthServiceFactory = ({ }); } + // Limit the number of keys to try to prevent abuse + const MAX_KEYS_TO_TRY = 10; + if (allSigningKeys.length > MAX_KEYS_TO_TRY) { + throw new UnauthorizedError({ + message: `Access denied: OIDC provider has ${allSigningKeys.length} signing keys. Tokens must include 'kid' header when provider has more than ${MAX_KEYS_TO_TRY} keys.` + }); + } + let lastError: Error | null = null; let verified = false;