Merge branch 'MDL-86679-500' of https://github.com/andimendunia/moodle into MOODLE_500_STABLE
This commit is contained in:
@@ -61,7 +61,8 @@ Feature: Basic OAuth2 functionality
|
||||
And I should see "device_authorization_endpoint"
|
||||
And I navigate to "Server > OAuth 2 services" in site administration
|
||||
And I click on "Configure user field mappings" "link" in the "Testing service" "table_row"
|
||||
And I should see "firstname" in the "givenname" "table_row"
|
||||
And I should see "firstname" in the "given_name" "table_row"
|
||||
And I should see "lastname" in the "family_name" "table_row"
|
||||
And I should see "idnumber" in the "sub" "table_row"
|
||||
And I should see "email" in the "email" "table_row"
|
||||
And I should see "lang" in the "locale" "table_row"
|
||||
|
||||
@@ -17,6 +17,7 @@
|
||||
namespace core\oauth2\client;
|
||||
|
||||
use core\oauth2\client;
|
||||
use stdClass;
|
||||
|
||||
/**
|
||||
* Custom oauth2 client for Microsoft to handle specific requirements.
|
||||
@@ -39,4 +40,35 @@ class microsoft extends client {
|
||||
}
|
||||
return parent::get_additional_upgrade_token_parameters();
|
||||
}
|
||||
|
||||
#[\Override]
|
||||
protected function map_userinfo_to_fields(stdClass $userinfo): array {
|
||||
// Microsoft returns different field names depending on account type:
|
||||
// - Work/School accounts: OpenID Connect standard (given_name, family_name)
|
||||
// - Personal accounts: Non-standard lowercase (givenname, familyname)
|
||||
// We need to check both formats to support all Microsoft account types.
|
||||
//
|
||||
// Additionally, we provide bidirectional fallback to handle sites that have not yet
|
||||
// run the database upgrade to update field mappings from the old format to the new format.
|
||||
|
||||
// Add fallback mappings for personal accounts if the standard fields are not present.
|
||||
if (empty($userinfo->given_name) && !empty($userinfo->givenname)) {
|
||||
$userinfo->given_name = $userinfo->givenname;
|
||||
}
|
||||
if (empty($userinfo->family_name) && !empty($userinfo->familyname)) {
|
||||
$userinfo->family_name = $userinfo->familyname;
|
||||
}
|
||||
|
||||
// Add reverse fallback for sites with old database mappings (givenname/familyname).
|
||||
// This ensures work/school accounts work even before the database upgrade runs.
|
||||
if (empty($userinfo->givenname) && !empty($userinfo->given_name)) {
|
||||
$userinfo->givenname = $userinfo->given_name;
|
||||
}
|
||||
if (empty($userinfo->familyname) && !empty($userinfo->family_name)) {
|
||||
$userinfo->familyname = $userinfo->family_name;
|
||||
}
|
||||
|
||||
// Call parent to handle the standard mapping.
|
||||
return parent::map_userinfo_to_fields($userinfo);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -59,8 +59,8 @@ class microsoft extends openidconnect implements issuer_interface {
|
||||
// Create the field mappings.
|
||||
$mapping = [
|
||||
'sub' => 'idnumber',
|
||||
'givenname' => 'firstname',
|
||||
'familyname' => 'lastname',
|
||||
'given_name' => 'firstname',
|
||||
'family_name' => 'lastname',
|
||||
'email' => 'email',
|
||||
'displayName' => 'alternatename',
|
||||
'officeLocation' => 'address',
|
||||
|
||||
@@ -1894,5 +1894,38 @@ function xmldb_main_upgrade($oldversion) {
|
||||
upgrade_main_savepoint(true, 2025041403.11);
|
||||
}
|
||||
|
||||
if ($oldversion < 2025041404.02) {
|
||||
// Fix Microsoft OAuth2 user field mappings to use OpenID Connect standard field names.
|
||||
// This corrects the mappings introduced in MDL-84432 which used non-standard field names
|
||||
// that only work with personal Microsoft accounts but not work/school (Entra ID) accounts.
|
||||
$userfieldmappings = [
|
||||
'firstname' => 'given_name',
|
||||
'lastname' => 'family_name',
|
||||
];
|
||||
$admin = get_admin();
|
||||
$adminid = $admin ? $admin->id : '0';
|
||||
$microsoftservices = $DB->get_records('oauth2_issuer', ['servicetype' => 'microsoft']);
|
||||
foreach ($microsoftservices as $microsoftservice) {
|
||||
$time = time();
|
||||
// Update user field mappings to use OpenID Connect standard field names.
|
||||
foreach ($userfieldmappings as $internalfieldname => $externalfieldname) {
|
||||
$fieldmap = ['issuerid' => $microsoftservice->id, 'internalfield' => $internalfieldname];
|
||||
$fieldmapid = $DB->get_field('oauth2_user_field_mapping', 'id', $fieldmap);
|
||||
if ($fieldmapid) {
|
||||
$fieldmap = array_merge($fieldmap, [
|
||||
'id' => $fieldmapid,
|
||||
'externalfield' => $externalfieldname,
|
||||
'timemodified' => $time,
|
||||
'usermodified' => $adminid,
|
||||
]);
|
||||
$DB->update_record('oauth2_user_field_mapping', $fieldmap);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Main savepoint reached.
|
||||
upgrade_main_savepoint(true, 2025041404.02);
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
+1
-1
@@ -29,7 +29,7 @@
|
||||
|
||||
defined('MOODLE_INTERNAL') || die();
|
||||
|
||||
$version = 2025041404.01; // 20250414 = branching date YYYYMMDD - do not modify!
|
||||
$version = 2025041404.02; // 20250414 = branching date YYYYMMDD - do not modify!
|
||||
// RR = release increments - 00 in DEV branches.
|
||||
// .XX = incremental changes.
|
||||
$release = '5.0.4+ (Build: 20251212)'; // Human-friendly version name
|
||||
|
||||
Reference in New Issue
Block a user