opnsense-ports/net/rubygem-omniauth-azure-oauth2/files/patch-lib-omniauth-strategies-azure_oauth2.rb
Franco Fichtner a304ae0404 */*: sync with upstream
Taken from: HardenedBSD
2018-01-02 23:31:39 +01:00

11 lines
455 B
Ruby

--- lib/omniauth/strategies/azure_oauth2.rb.orig 2017-12-06 18:00:39 UTC
+++ lib/omniauth/strategies/azure_oauth2.rb
@@ -61,7 +61,7 @@ module OmniAuth
def raw_info
# it's all here in JWT http://msdn.microsoft.com/en-us/library/azure/dn195587.aspx
- @raw_info ||= ::JWT.decode(access_token.token, nil, false).first
+ @raw_info ||= ::JWT.decode(access_token.token, nil, false, algorithm: 'RS256').first
end
end