las2peer icon indicating copy to clipboard operation
las2peer copied to clipboard

[ENH] Make username claim configureable on a oidc provider basis

Open ThoreKr opened this issue 3 years ago • 0 comments

Motivation

The authentication manager takes a strong assumption on the preferred_username. It requires this claim to be present and unique. Which both isn't safe to assume. Some OIDC providers, such as google, do not provide this claim.

Specification

Extend the configuration options on the oidc providers to allow to specify the claim which should be used for the agents username.

This might be inspired by the parameters requested by synapse.

Finalised state

Login with other identity providers than keycloak should be possible.

ThoreKr avatar May 26 '21 21:05 ThoreKr