Merge branch 'MDL-86679-500' of https://github.com/andimendunia/moodle into MOODLE_500_STABLE

This commit is contained in:
Huong Nguyen
2025-12-15 08:47:53 +07:00
5 changed files with 70 additions and 4 deletions
@@ -61,7 +61,8 @@ Feature: Basic OAuth2 functionality
And I should see "device_authorization_endpoint"
And I navigate to "Server > OAuth 2 services" in site administration
And I click on "Configure user field mappings" "link" in the "Testing service" "table_row"
And I should see "firstname" in the "givenname" "table_row"
And I should see "firstname" in the "given_name" "table_row"
And I should see "lastname" in the "family_name" "table_row"
And I should see "idnumber" in the "sub" "table_row"
And I should see "email" in the "email" "table_row"
And I should see "lang" in the "locale" "table_row"
+32
View File
@@ -17,6 +17,7 @@
namespace core\oauth2\client;
use core\oauth2\client;
use stdClass;
/**
* Custom oauth2 client for Microsoft to handle specific requirements.
@@ -39,4 +40,35 @@ class microsoft extends client {
}
return parent::get_additional_upgrade_token_parameters();
}
#[\Override]
protected function map_userinfo_to_fields(stdClass $userinfo): array {
// Microsoft returns different field names depending on account type:
// - Work/School accounts: OpenID Connect standard (given_name, family_name)
// - Personal accounts: Non-standard lowercase (givenname, familyname)
// We need to check both formats to support all Microsoft account types.
//
// Additionally, we provide bidirectional fallback to handle sites that have not yet
// run the database upgrade to update field mappings from the old format to the new format.
// Add fallback mappings for personal accounts if the standard fields are not present.
if (empty($userinfo->given_name) && !empty($userinfo->givenname)) {
$userinfo->given_name = $userinfo->givenname;
}
if (empty($userinfo->family_name) && !empty($userinfo->familyname)) {
$userinfo->family_name = $userinfo->familyname;
}
// Add reverse fallback for sites with old database mappings (givenname/familyname).
// This ensures work/school accounts work even before the database upgrade runs.
if (empty($userinfo->givenname) && !empty($userinfo->given_name)) {
$userinfo->givenname = $userinfo->given_name;
}
if (empty($userinfo->familyname) && !empty($userinfo->family_name)) {
$userinfo->familyname = $userinfo->family_name;
}
// Call parent to handle the standard mapping.
return parent::map_userinfo_to_fields($userinfo);
}
}
+2 -2
View File
@@ -59,8 +59,8 @@ class microsoft extends openidconnect implements issuer_interface {
// Create the field mappings.
$mapping = [
'sub' => 'idnumber',
'givenname' => 'firstname',
'familyname' => 'lastname',
'given_name' => 'firstname',
'family_name' => 'lastname',
'email' => 'email',
'displayName' => 'alternatename',
'officeLocation' => 'address',
+33
View File
@@ -1894,5 +1894,38 @@ function xmldb_main_upgrade($oldversion) {
upgrade_main_savepoint(true, 2025041403.11);
}
if ($oldversion < 2025041404.02) {
// Fix Microsoft OAuth2 user field mappings to use OpenID Connect standard field names.
// This corrects the mappings introduced in MDL-84432 which used non-standard field names
// that only work with personal Microsoft accounts but not work/school (Entra ID) accounts.
$userfieldmappings = [
'firstname' => 'given_name',
'lastname' => 'family_name',
];
$admin = get_admin();
$adminid = $admin ? $admin->id : '0';
$microsoftservices = $DB->get_records('oauth2_issuer', ['servicetype' => 'microsoft']);
foreach ($microsoftservices as $microsoftservice) {
$time = time();
// Update user field mappings to use OpenID Connect standard field names.
foreach ($userfieldmappings as $internalfieldname => $externalfieldname) {
$fieldmap = ['issuerid' => $microsoftservice->id, 'internalfield' => $internalfieldname];
$fieldmapid = $DB->get_field('oauth2_user_field_mapping', 'id', $fieldmap);
if ($fieldmapid) {
$fieldmap = array_merge($fieldmap, [
'id' => $fieldmapid,
'externalfield' => $externalfieldname,
'timemodified' => $time,
'usermodified' => $adminid,
]);
$DB->update_record('oauth2_user_field_mapping', $fieldmap);
}
}
}
// Main savepoint reached.
upgrade_main_savepoint(true, 2025041404.02);
}
return true;
}
+1 -1
View File
@@ -29,7 +29,7 @@
defined('MOODLE_INTERNAL') || die();
$version = 2025041404.01; // 20250414 = branching date YYYYMMDD - do not modify!
$version = 2025041404.02; // 20250414 = branching date YYYYMMDD - do not modify!
// RR = release increments - 00 in DEV branches.
// .XX = incremental changes.
$release = '5.0.4+ (Build: 20251212)'; // Human-friendly version name