Skip to content

Add some generic bits about integrating with external IDP#227

Merged
micbar merged 3 commits intoopencloud-eu:mainfrom
rhafer:issue/97
Apr 14, 2025
Merged

Add some generic bits about integrating with external IDP#227
micbar merged 3 commits intoopencloud-eu:mainfrom
rhafer:issue/97

Conversation

@rhafer
Copy link
Copy Markdown
Member

@rhafer rhafer commented Apr 10, 2025

This takes some bits from the keycloak page which are bascially relevant for integrating with any external IDP and puts them in a separate section.
Also adds some bits about the claim based role assignment setup (taken from the proxy's service README).

@rhafer rhafer requested review from Svanvith and micbar April 10, 2025 15:29
@rhafer rhafer self-assigned this Apr 10, 2025
Copilot AI review requested due to automatic review settings April 10, 2025 15:29
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

Comments suppressed due to low confidence (4)

docs/admin/30-configuration/30-authentication-and-user-management/10-external-idp.md:15

  • Typo in 'openid-configuraton'; consider changing it to 'openid-configuration'.
- `PROXY_OIDC_REWRITE_WELLKNOWN`: Set this to `true` to expose the Identity Providers `.well-known/openid-configuraton` via the OpenCloud base url.

docs/admin/30-configuration/30-authentication-and-user-management/10-external-idp.md:17

  • Typo in 'do now yet support'; consider revising to 'do not yet support'.
  help the oidc client, that do now yet support discovery via webfinger to locate the Identity Provider's configuration.

docs/admin/30-configuration/30-authentication-and-user-management/10-external-idp.md:35

  • Typo in 'afore mentioned'; consider changing it to 'aforementioned'.
the mapping between the OIDC and LDAP users happens base on the afore mentioned `PROXY_USER_CS3_CLAIM` settings.

docs/admin/30-configuration/30-authentication-and-user-management/10-external-idp.md:37

  • Typo in 'charcters'; consider changing it to 'characters'.
Set `GRAPH_USERNAME_MATCH` to `none` when `PROXY_AUTOPROVISION_ACCOUNTS` is set to `true` to disable OpenCloud's default restrictions on allowed charcters in usernames.

This takes some bits from the keycloak page which are bascially relevant
for integrating with any external IDP and puts them in a separate
section.
Also adds some bits about the claim based role assignment setup (taken
from the proxy's service README).
Co-authored-by: Alex <abackermann91@gmail.com>
Co-authored-by: Phil Davis <phil@jankaritech.com>
Comment thread docs/admin/30-configuration/30-authentication-and-user-management/30-keycloak.md Outdated
@micbar micbar requested a review from AlexAndBear April 14, 2025 14:26
@micbar micbar merged commit af65d9c into opencloud-eu:main Apr 14, 2025
1 check passed
@openclouders openclouders mentioned this pull request Apr 14, 2025
1 task
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants