OPENID CONNECT · LAB
Carry a second issuer's statement in UserInfo
Plan Lab Photos carrying a statement signed by Lab Mail inside its UserInfo response, and today see the authority problem with a normal claim and get a real signed statement from a second issuer.
PlannedUses both lab tenants
The lesson
Builds on: Connecting a sign-in to an account.
New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.
Planned. The core of this lab waits on platform features that are not built yet. The planned walkthrough shows exactly how it will run; Do today is a real exercise you can do now.
- G63 Aggregated and distributed claims (trusted claims-provider registry)
- G19 `claims` request parameter
- G66 Second lab tenant for every learner: additional tenants need a paid subscription or a BTL grant, so labs that use Lab Mail cannot be completed by an ordinary learner yet
Needs a second tenant. This lab also uses Lab Mail, a second tenant. Additional tenants currently need a paid subscription or a BTL grant, so you may not be able to do the Lab Mail steps yet (gap G66).
Request console
Requests in this lab can be sent from this page to your tenant: open one and choose Send. Fill in the values below first. They stay in this page's memory and are gone when you leave; secrets are never stored or sent anywhere except the request you send.
Setup
Tenants issue normal claims only today: no _claim_names or _claim_sources, no claim_types_supported, no trusted claims provider configuration (G63), and no claims parameter to ask for one claim at checkout (G19). In this lab Lab Mail plays the lesson's university, the party that knows whether Ava is enrolled.
source ~/btl-oidc.shand runbtl-lab callbackbefore each sign-in.Once G63 exists: in Lab Mail, add a claim mapping
lab_enrolledfor its users and a statement profile that issues it as a JWT with noaudand nosub. In Lab Photos, add Lab Mail as a claims provider: its issuer, its JWKS,RS256, and the claim names it may vouch for. Then link Ava's Lab Photos account to her stored Lab Mail statement.
Planned walkthrough
Read Lab Photos' discovery document:
claim_types_supportedlistsnormalandaggregated.Ask for the claim only at checkout, with the
claimsparameter for UserInfo:
signin "claims=$(enc '{"userinfo":{"lab_enrolled":null}}')"
Lab Photos asks Ava whether to share her Lab Mail enrollment with lab-collage. She agrees.
Read UserInfo:
curl -s -H "Authorization: Bearer $TOKEN" "$ISSUER/oidc/userinfo" | jq '{sub, _claim_names, sources: (._claim_sources | map_values(keys))}'
_claim_names maps lab_enrolled to src1, and _claim_sources.src1 has a JWT member.
Why it matters: the claim is not among the normal claims. Two special members say where to find it, and the label says nothing about who signed it.
Decode the embedded JWT with
btl-lab decode: Lab Mail'siss,iat,expand the claim, with nosuband noaud. Lab Photos' response is what ties it to Ava.Run the checkout again and decline sharing: the claim is simply absent, and nothing errors.
Do today
The authority problem. In Lab Photos, create the scope
lab-tmp-enrollmentand add it tolab-collage's allowed scopes. In the ID token manager assigned tolab-collage, add a claim mappinglab_enrolledwith the expressiontrue, limited to that scope and to UserInfo. Sign in with it and read UserInfo:
SCOPE="openid lab-tmp-enrollment"
signin
redeem '<code>'
curl -s -H "Authorization: Bearer $TOKEN" "$ISSUER/oidc/userinfo" | jq '{sub, lab_enrolled}'
"lab_enrolled": true, asserted by Lab Photos, which holds no enrollment records at all.
Why it matters: a provider can only repeat a fact it does not own. The lesson wants each fact from the party that knows it.
A statement from the party that knows. In Lab Mail, add the same mapping (
lab_enrolled, expressiontrue) to the ID token manager assigned tolab-mail-collage, for ID tokens. Sign in tolab-mail-collageas Ava Lin and keep the ID token:
ISSUER_A=$ISSUER CLIENT_A=$CLIENT_ID SECRET_A=$CLIENT_SECRET
ISSUER=$ISSUER2 CLIENT_ID=$MAIL_CLIENT_ID CLIENT_SECRET=$MAIL_CLIENT_SECRET SCOPE="openid"
signin
redeem '<code>'
MAIL_STATEMENT=$ID_TOKEN
btl-lab decode "$MAIL_STATEMENT"
iss is Lab Mail and the header names Lab Mail's kid. It also carries aud, sub and nonce. Keep MAIL_STATEMENT: Validate an embedded claims-provider JWT uses it.
Why it matters: this is a real signed statement from a second issuer, and also exactly the different kind of JWT the next lesson warns about.
Ask Lab Photos which claim types it supports:
GET$ISSUER/.well-known/openid-configuration
Open in console
GET $ISSUER/.well-known/openid-configurationThere is no claim_types_supported member, which means normal claims only.
Switch back to Lab Photos (
ISSUER=$ISSUER_A CLIENT_ID=$CLIENT_A CLIENT_SECRET=$SECRET_A SCOPE="openid profile email").
Break it
Planned, once G63 exists: ask Lab Photos for the claim after Ava's stored statement has expired. The claim is absent, not an error, and the relying party offers its other way to prove enrollment.
Check your work
Today: Lab Photos' UserInfo showed lab_enrolled asserted by Lab Photos itself; MAIL_STATEMENT decodes with Lab Mail's issuer and key; Lab Photos' discovery has no claim_types_supported. Audit in each tenant shows tenant.oauth.id_token_managers.update for the mappings.
Once G63 exists, Lab Photos' Audit records UserInfo served with an aggregated source and Ava's decision to share it.
Cleanup
In Lab Photos, remove the
lab_enrolledmapping, removelab-tmp-enrollmentfromlab-collage, and delete the scope.Keep the Lab Mail mapping until you finish the next lab, then remove it.
Missing infrastructure
G63 (aggregated and distributed claims). A claims provider registry per tenant (issuer, JWKS, algorithms, permitted claim names), stored statements or references per user,
_claim_namesand_claim_sourcesin ID tokens and UserInfo,claim_types_supportedin discovery, a consent choice for each source, and audit events.G19 (
claimsrequest parameter). Asking for the claim only when it is needed, at checkout.G66 Second lab tenant: this lab uses Lab Mail, a second tenant. Additional tenants currently need a paid subscription or a BTL grant, so an ordinary learner can do only the Lab Photos steps until every learner can have a second lab tenant.