Topic7 problems

OIDC Federation

7 incident problems about OIDC Federation. Start with the reviewed ones.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

All problems (7)

SECURITY-1192Auth hardening breaks API clientsA public hardening checklist changed proxy header behavior. Browser auth appears fine, but downstream API flows now break because the app no longer sees the scheme and host headers it expects.SecurityIntermediate18 minProSECURITY-1201OIDC issuer update looks complete but one validator still pins the old issuer URLMost auth flows recover after an issuer migration, yet one proxy or sidecar still rejects tokens because it continues to trust the previous issuer location.SecurityAdvanced22 minProSECURITY-1184OIDC login callback breaks behind proxyCommunity fixes focus on the identity provider, but the real break is that the edge proxy is building the wrong callback URL.SecurityAdvanced22 minProSECURITY-1195Cloud role assumption succeeds in one region and fails in anotherA cloud auth rollout followed community guidance and worked in one region. A second region fails because the trust condition still expects the previous audience or issuer pattern.SecurityAdvanced23 minProSECURITY-1196JWT validation fails only on one proxy pathA key rotation followed public best practices. One proxy path still rejects tokens because it holds an older JWKS view than the rest of the platform.SecurityAdvanced21 minProCICD-1197OIDC deploy works for the workflow caller but fails inside a reusable deployment workflowThe top-level job can authenticate to AWS, yet the reusable deployment workflow fails because the assumed identity boundary differs inside the called workflow.CI/CDAdvanced26 minProCICD-1181GitHub Actions OIDC trust works on main but fails on pull_requestThe same AWS deploy workflow succeeds on main and fails on pull_request because the OIDC token subject no longer matches the IAM trust policy.CI/CDAdvanced28 minPro