I have an Azure linux_web_app set up with so-called "Easy Auth" set that authentication is required and unauthenticated hits are redirected to login.
When I log in after hitting /, I'm redirected back to the /.auth/login/aad/callback route with errors that response_type id_token is not allowed. I KNOW THIS. I don't want to allow the hybrid flow. But I cannot figure out why the hybrid flow is being demanded.
If I set implicit_id_token_issuance_enabled = true, yes I can log in, but that shouldn't be necessary for this type = "Web"-only redirect_uris:
Implicit grant and hybrid flows
The implicit grant allows an application to request a token directly from the authorization endpoint. It is only recommended for browser-based single-page applications (SPAs).
-- azure portal
I've tried setting the following, which works to override the initial call, but then in the auth callback instead of an error we go into a loop where aad says "you're logged in" but easyauth says "I don't have everything I want (the id_token) so redirect to aad":
active_directory_v2 { ...
login_parameters = {
response_type="code"
}
I just want authorization code flow, please.