mirror of
https://github.com/zitadel/zitadel.git
synced 2026-08-17 16:35:14 -05:00
# Which Problems Are Solved
Expose impersonating actor to `preAccessToken` and `preUserinfo`
actions.
# How the Problems Are Solved
Provide the `actor` information already present in the OIDC session
model of JWT token to the relevant actions. Both goja-based actions "v1"
and webhook based execution targets carry the actor information now.
Actor remains null in case of non-impersonated tokens. Actor may contain
nested actors to display a delegation chain of impersonators.
# Additional Changes
- dba6261c8e: refactor `userinfoFlows` to
reduce complexity, add test coverage and solve a couple of potential
bugs.
- `getClientId` in actions was previously undocumented. Added to
documentation.
- A skill that reproduces manual testing using webhook.site or a local
sink.
# Additional Context
- Closes https://github.com/zitadel/zitadel/issues/12097
---------
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Wim Van Laer <wim+github@zitadel.com>
Skills
Self-contained runbooks for manual verification of Zitadel features against a local test instance. Each skill is a Markdown file describing what it verifies, what it needs and how to run it, usually next to a script that does the work.
They are deliberately tool neutral: plain Markdown and plain shell, no assistant-specific frontmatter or directory layout. Read one and follow it yourself, or hand it to whichever AI assistant you use.
| Skill | Verifies |
|---|---|
| test-actor-in-action-v2.md | The impersonation actor is passed to Actions v2 execution targets and appears in the token claims. |
Conventions for new skills
- Local only. A skill may create users, flip instance settings and delete things. Refuse to
run against anything but
localhost, and enforce it in the script rather than only saying it in the prose. - Ask first. Print what will be created and require a confirmation, with a
--yesescape hatch for non-interactive use. - Clean up. Remove what you created, including on failure, and restore settings you changed.
Offer a
--keepflag for debugging. - Assume a clean slate. Create the users, projects and clients you need instead of relying on fixtures that happen to exist on the author's machine.
- Fail loudly and usefully. Turn Zitadel's error envelopes into messages that say what to do next, and assert explicitly rather than leaving output for a human to eyeball.