Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

OPENID CONNECT · LAB

Reassign an email address and see why only issuer and subject identify a person

Move [email protected] from Ava to Ben, watch an email-keyed lookup hand over the wrong account, see the tenant refuse to reuse a subject, and trim lab-collage to the claims it needs.

Partly readyUses your lab tenant

The lesson

Builds on: Public and pairwise subject identifiers.

New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.

Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.

Your progress

Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.

  1. Give Ava a new email address

    Recorded as tenant.users.update succeeded.

  2. Give Ben the address Ava gave up

    Recorded as tenant.users.update succeeded.

  3. Let lab-collage's manager use email as the subject, in a contained step

    Recorded as tenant.oauth.id_token_managers.update succeeded.

  4. The tenant refuses to give an email-shaped subject to a second person

    Recorded as oauth.token failed (subject_in_use) for lab-collage.

  5. Restore the default subject

    Recorded as tenant.oauth.id_token_managers.update succeeded.

Setup

  1. You need lab-collage with its lab-collage ID token manager issuing the default sub, Ava and Ben in Lab Photos, rp_discover and the redefined helpers, links.json and account.json. Run rp_discover "$ISSUER" and keep btl-lab callback running.

  2. Sign Ava in once with signin_url 'openid%20email' and exchange. Make sure links.json holds her (iss, sub) pair and account.json holds her email address.

  3. Press Start.

Walkthrough

  1. Reassign an address. In Users, change Ava's email to [email protected], then change Ben's email to [email protected]. Each change ends that user's sessions and revokes their tokens.

  1. Sign in through lab-collage as the new owner of [email protected], using Ben's password, and validate the token. It says email: [email protected] with Ben's sub. Look the person up both ways:

    • By email in account.json: it finds Ava's account and would hand it to Ben.

    • By (iss, sub) in links.json: it finds nothing, so this is a new customer.

Why it matters: every value in that token was true. Only the issuer and subject pair stayed tied to the right person.

  1. Read email_verified for both users: false. An administrator's change clears verification. The claim describes a moment of verification, not current ownership, and only the JSON value true counts as verified.

  1. A contained step: let the provider use email as the subject. On the lab-collage ID token manager, assigned only to lab-collage, set the standard claim sub to the attribute Email. Change Ben's email back to [email protected], then Ava's back to [email protected], sign in as Ava, and the token says sub: [email protected].

  1. Reassign again, as in step 1, and sign in as Ben (now [email protected]). The code is issued, but the token request fails with 500 and server_error.

Why it matters: the tenant never gives a sub to a second person, as OpenID Connect requires, so an email-based subject turns reassignment into an outage instead of an account takeover. Sign in as Ava (now [email protected]): her sub has changed, so the collage app no longer finds her account either. Email is unstable whichever side uses it.

Restore: set sub on the lab-collage ID token manager back to the default (the user ID), then change Ben's email back to [email protected] and Ava's back to [email protected], in that order. The email-shaped subjects stay bound to the users that first received them and are never issued to anyone else.

  1. Collect less. Change the collage app's sign-in to openid%20email, adding profile only where a greeting needs it. Keep the account record to an allowlist, and write the sign-in log line with only what happened:

curl -s "$USERINFO_ENDPOINT" -H "Authorization: Bearer $TOKEN" | jq '{given_name, email, email_verified}' > account.json
jq -cn --arg i "$ISSUER" --arg s '<sub>' --arg c "$(openssl rand -hex 8)" '{event: "sign_in.completed", message: "Sign-in completed", issuer: $i, subject: $s, stage: "session", outcome: "succeeded", correlation_id: $c}'
  1. Read the provider's records the same way. Open a few oauth.authorize, oauth.token and oidc.userinfo entries in Lab Photos Audit. They carry user and client IDs, outcomes and request IDs, and no names, email addresses or token values.

Planned walkthrough

This step runs once directory claims include updated_at (G21).

  1. Change Ava's last name in Users, sign in again, and compare updated_at with the value stored in account.json. The new value is larger, so the collage app refreshes its copies only then. Sign in once more without a change: updated_at is unchanged, and the copies stay as they are.

Break it

Steps 2 and 5 are the deliberate failures: an email-keyed lookup that hands over an account, and an email-shaped subject that turns reassignment into an outage. Before you continue, make sure the Restore in step 5 is done: lab-collage issues the default sub, and Ava is [email protected] again.

Check your work

Press Check my progress. It looks for, in order: two tenant.users.update records for the email reassignment, the lab-collage ID token manager switched to an email subject, oauth.token failed with subject_in_use for lab-collage, and the manager restored to the default subject.

links.json should still map Ava's original (iss, sub) to her account.

Cleanup

  1. Confirm that Ava is [email protected], Ben is [email protected], and the lab-collage ID token manager issues the default sub.

  2. Delete any copies of account.json you no longer need.

Missing infrastructure

  • G21 (group and custom-attribute claims): there is no updated_at claim. Directory users record a last-change time, but it is not a claim attribute. The planned step will refresh the collage app's copies only when updated_at grows, as the lesson's "Collecting less" section describes. Today a relying party can only refresh its copies on every sign-in.

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab