Skip to content

feat: Add support for OIDC - #266

Merged
lordmathis merged 12 commits into
mainfrom
feat/oidc
Oct 3, 2026
Merged

lordmathis merged 12 commits into
mainfrom
feat/oidc

Conversation

@lordmathis

Copy link
Copy Markdown
Owner

Closes #102

Comment thread pkg/server/oidc.go Fixed
Every user the IdP authenticates could log in with full admin access.
Optionally require membership in one of auth.oidc.allowed_groups,
checked against the ID token's groups claim (configurable via
groups_claim, default "groups").

- Empty allowed_groups keeps current behavior (all users admitted)
- Fail closed: missing/empty claim denies with 403; malformed claim
  is a 502 (IdP misconfiguration)
- Enforced at login only; group removal applies at session expiry
- Denials log token groups, claim name consulted, and the token's
  claim names so a wrong groups_claim is diagnosable from the log
@lordmathis
lordmathis marked this pull request as ready for review October 3, 2026 20:25
@lordmathis
lordmathis merged commit f52626e into main Oct 3, 2026
10 checks passed
@lordmathis
lordmathis deleted the feat/oidc branch October 3, 2026 20:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add OIDC authentication

2 participants