-
Notifications
You must be signed in to change notification settings - Fork 7.9k
Closed
Labels
area/authenticationIndicates an issue on Authentication areaIndicates an issue on Authentication areakind/bugCategorizes a PR related to a bugCategorizes a PR related to a bugpriority/importantMust be worked on very soonMust be worked on very soonrelease/26.0.1release/26.1.0status/bumped-by-botteam/core-clients
Description
Before reporting an issue
- I have read and understood the above terms for submitting issues, and I understand that my issue may be closed without action if I do not follow them.
Area
authentication
Describe the bug
When users log in using a custom Identity Provider (IDP), if the IDP returns the email address with uppercase letters, it causes a case sensitivity issue. This discrepancy leads to the system treating the email as different from the previously registered or verified email, even if the characters are the same but in different cases (e.g., "[email protected]" vs. "[email protected]"). As a result of this case sensitivity, users are prompted to verify their email address every time they log in.
Version
25.0.2
Regression
- The issue is a regression
Expected behavior
The verification of email should only happen when the user signs up.
Actual behavior
The verification of email happens every time the user logs in.
How to Reproduce?
- Create a user on Keycloak.
- Set up an IDP.
- Login using an IDP with the same email with upper case letters.
- Log out and log in again.
Anything else?
No response
spajxo, keycloak-github-bot, axscm, Tricer1, MichalMeszaros and 8 more
Metadata
Metadata
Assignees
Labels
area/authenticationIndicates an issue on Authentication areaIndicates an issue on Authentication areakind/bugCategorizes a PR related to a bugCategorizes a PR related to a bugpriority/importantMust be worked on very soonMust be worked on very soonrelease/26.0.1release/26.1.0status/bumped-by-botteam/core-clients