[PR #6422] [MERGED] [management] Skip JWT group evaluation for embedded-IdP local users #28199

Open
opened 2026-08-05 08:05:57 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/6422
Author: @bcmmbaga
Created: 6/12/2026
Status: Merged
Merged: 6/15/2026
Merged by: @bcmmbaga

Base: mainHead: fix/jwt-allow-groups-skip-local-idp-users


📝 Commits (3)

  • 3483ba9 add helper for local user subject
  • 4755a18 skip JWT group checks for local Dex user
  • fce35c4 skip JWT group sync for local Dex user

📊 Changes

6 files changed (+101 additions, -3 deletions)

View changed files

📝 idp/dex/provider.go (+10 -1)
📝 idp/dex/provider_test.go (+20 -0)
📝 management/server/account.go (+5 -1)
📝 management/server/account_test.go (+23 -0)
📝 management/server/auth/manager.go (+5 -1)
📝 management/server/auth/manager_test.go (+38 -0)

📄 Description

Describe your changes

When JWT group sync is enabled with a restrictive JWTAllowGroups list, the local owner of an embedded-IdP (Dex) deployment can get locked out. The allow-groups check runs account-wide but local password users do not receive
external IdP group claims, so they can't satisfy the allowed list.

This skips JWT group evaluation for local Dex users so the restriction and JWT group sync continue to apply to external-IdP users as intended.

Fixes #5337

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

Bug Fixes

  • Local embedded Dex users are now properly excluded from JWT group synchronization and are no longer subject to JWT group-based access control restrictions. This ensures that local Dex authentication accounts operate independently from JWT group policies configured in the system.
  • Improved system reliability with enhanced identification of local Dex users across authentication and authorization components.

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/6422 **Author:** [@bcmmbaga](https://github.com/bcmmbaga) **Created:** 6/12/2026 **Status:** ✅ Merged **Merged:** 6/15/2026 **Merged by:** [@bcmmbaga](https://github.com/bcmmbaga) **Base:** `main` ← **Head:** `fix/jwt-allow-groups-skip-local-idp-users` --- ### 📝 Commits (3) - [`3483ba9`](https://github.com/netbirdio/netbird/commit/3483ba9823004cb248043f723f0ab8f1adca122e) add helper for local user subject - [`4755a18`](https://github.com/netbirdio/netbird/commit/4755a1815e2d84252ade0e1c27f2ffc937912534) skip JWT group checks for local Dex user - [`fce35c4`](https://github.com/netbirdio/netbird/commit/fce35c4b7f954202f7084b2dd2bc1b614c631481) skip JWT group sync for local Dex user ### 📊 Changes **6 files changed** (+101 additions, -3 deletions) <details> <summary>View changed files</summary> 📝 `idp/dex/provider.go` (+10 -1) 📝 `idp/dex/provider_test.go` (+20 -0) 📝 `management/server/account.go` (+5 -1) 📝 `management/server/account_test.go` (+23 -0) 📝 `management/server/auth/manager.go` (+5 -1) 📝 `management/server/auth/manager_test.go` (+38 -0) </details> ### 📄 Description ## Describe your changes When JWT group sync is enabled with a restrictive `JWTAllowGroups` list, the local owner of an embedded-IdP (Dex) deployment can get locked out. The allow-groups check runs account-wide but local password users do not receive external IdP group claims, so they can't satisfy the allowed list. This skips JWT group evaluation for local Dex users so the restriction and JWT group sync continue to apply to external-IdP users as intended. ## Issue ticket number and link Fixes #5337 ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Bug Fixes - Local embedded Dex users are now properly excluded from JWT group synchronization and are no longer subject to JWT group-based access control restrictions. This ensures that local Dex authentication accounts operate independently from JWT group policies configured in the system. - Improved system reliability with enhanced identification of local Dex users across authentication and authorization components. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 08:05:57 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#28199