Repository navigation
Configurable OIDC username claim (preferred_username vs. name) #1677
Replies: 1 comment
|
Done: there's a new |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Problem
TREK currently uses the OIDC
nameclaim as the account's username/display name.For providers where
nameis the full given+family name (e.g. Pocket ID, and manyother OIDC IdPs following the standard claim set), this results in usernames like
"Jane Doe" instead of a clean handle, with no way to change it — the profile gets
re-synced from the OIDC claims on every login (as fixed in #1274 for the admin
role), so manually editing the username in Admin → Users doesn't stick.
Proposed solution
Add an
OIDC_USERNAME_CLAIMenvironment variable (default:name, for backwardscompatibility) that lets admins choose which claim populates the username field,
e.g.:
This is the same pattern already used by other self-hosted apps that integrate
with Pocket ID and similar OIDC providers (Nextcloud's --mapping-uid, Portainer,
Semaphore UI's username_claim, Outline's OIDC_USERNAME_CLAIM).
Alternative
A fallback chain (e.g. try
preferred_username, then fall back toname) wouldalso solve this without requiring configuration for providers that don't send
preferred_username.All reactions