Skip to content

fix(oidc): parse JSON array strings in mapstructure decode hook - #67

Merged
philipgough merged 2 commits into
rhobs:rhobs-obs-api-konfluxfrom
redhat-chai-bot:chai-bot/fix-stringorslice-decode-hook
Oct 2, 2026
Merged

philipgough merged 2 commits into
rhobs:rhobs-obs-api-konfluxfrom
redhat-chai-bot:chai-bot/fix-stringorslice-decode-hook

Conversation

@redhat-chai-bot

Copy link
Copy Markdown

Summary

Fix stringOrSliceDecodeHook to correctly parse JSON array strings when loading tenant config via mapstructure.Decode.

Problem

When GroupClaim is set to ["org_id", "rh-org-id"] in the config (generated by configuration_go where GroupClaim is typed string), the YAML serializes it as a quoted string:

groupClaim: '["org_id", "rh-org-id"]'

The stringOrSliceDecodeHook wraps this as StringOrSlice{"[\"org_id\", \"rh-org-id\"]"} — a single-element slice containing the literal JSON text. The runtime then looks for a claim named ["org_id", "rh-org-id"] in the JWT, which doesn't exist, returning "group cannot be empty".

Fix

In the case string: branch, try json.Unmarshal first to detect JSON-encoded arrays before falling back to single-element wrapping:

case string:
    var arr []string
    if err := json.Unmarshal([]byte(v), &arr); err == nil {
        return StringOrSlice(arr), nil
    }
    return StringOrSlice{v}, nil

Tests

6 new test cases:

  • 3 integration tests via TestCheckAuthMapstructureJSONArrayString (full OIDC flow with mapstructure-loaded config)
  • 3 unit tests via TestStringOrSliceDecodeHookJSONArrayString (decode hook directly)

Related


AI-generated. Review for accuracy.

@philipgough requested from Slack

redhat-chai-bot and others added 2 commits October 2, 2026 09:35
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@philipgough philipgough left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@philipgough
philipgough merged commit e27c0af into rhobs:rhobs-obs-api-konflux Oct 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants