Skip to content

bug: OIDC users are identified by sub/iss claims which may not be stable #19014

@aaronlehmann

Description

@aaronlehmann

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

Our OIDC provide provides a userId claim which acts as a primary key to identify users, but the sub claim will change if the user's email address changes. When this happens, Coder treats it as a new user, and the user loses access to their existing workspaces.

Relevant Log Output

Expected Behavior

No response

Steps to Reproduce

Change a user's email address

Environment

v2.23.2

Additional Context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageIssue that require triage

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions