mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-11 05:41:50 +09:00
Backport #39498 by @SHIVANSHGARG07 The OIDC discovery document at `/.well-known/openid-configuration` advertised `id_token` in `response_types_supported`, but `/login/oauth/authorize` only implements the authorization code flow and rejects any other response_type with `unsupported_response_type`. This mismatch caused OIDC client libraries that rely on discovery to attempt the implicit flow and fail silently. This removes `id_token` from `response_types_supported` so discovery matches actual server behavior, and adds an integration test asserting `response_type=id_token` is rejected consistently. Manually verified: rebuilt Gitea, registered an OAuth2 app, confirmed `/.well-known/openid-configuration` no longer lists `id_token`, and confirmed `/login/oauth/authorize?...&response_type=id_token` still correctly returns `error=unsupported_response_type`. Fixes #39482. <!-- Before submitting: - Target the `main` branch; release branches are for backports only. - Use a Conventional Commits title, e.g. `fix(repo): handle empty branch names`. - Read the contributing guidelines: https://github.com/go-gitea/gitea/blob/main/CONTRIBUTING.md - Documentation changes go to https://gitea.com/gitea/docs Describe your change below and link any issue it fixes. --> Co-authored-by: Shivansh Garg <shivanshgarg587@gmail.com>