OIDC - Wild card support for login redirects with Azure as an IDP

Uses: Kong Gateway
TL;DR

How can I support wildcard login redirects with Azure AD using the OIDC plugin?

Azure AD doesn’t support wildcard redirect URIs. Configure the OIDC plugin with a static redirect_uri, and set login_action=redirect and preserve_query_args=true so Kong performs an additional redirect to the originally requested URL after authentication.

Problem

We use Azure as our OpenID Connect (OIDC) Identity Provider (IDP). Azure documentation states they have no support for wild card login redirects, is there any workaround for this?

Solution

The following config for the OIDC plugin will perform an additional redirect (to the originally requested URL) at the Kong side once the OIDC has performed its authentication:

config.redirect_uri=<static-url> -- as adfs does not support wildcards
config.login_action=redirect     -- to make extra redirecting after the login
config.preserve_query_args=true  -- to preserve possible query args from original url
config.login_tokens=             -- set it to null so that plugin does not add any tokens to redirection

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!