← 返回首页
Extract groups and namespaces claims from JWT token · Issue #6088 · feast-dev/feast · GitHub
Skip to content

Navigation Menu

Toggle navigation
Sign in
Appearance settings
Search or jump to...

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Include my email address so I can be contacted

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
Resetting focus

Extract groups and namespaces claims from JWT token #6088

New issue
New issue

Description

Is your feature request related to a problem? Please describe.

OidcTokenParser only extracts username and roles from the JWT. The groups and namespaces claims are ignored, so GroupBasedPolicy and NamespaceBasedPolicy never match for OIDC-authenticated users.

Describe the solution you'd like

Extract groups and namespaces claims from the decoded JWT in OidcTokenParser.user_details_from_access_token() and pass them to the User object. Default to empty list if the claims are absent.

Describe alternatives you've considered

None — the User model, policy classes, and enforcer already support groups and namespaces. Only the OIDC parser is missing the extraction.

Additional context

Affected file: sdk/python/feast/permissions/auth/oidc_token_parser.py

Metadata

Metadata

Assignees

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions

    Footer

    © 2026 GitHub, Inc.