OIDC integration
With OIDC on, the identity provider is a second way past the first factor. It never replaces the second factor.
- Login uses PKCE; the app checks the provider's signed ID token (see
OIDC_SERVER_METADATA_URLin the configuration table). - Each person links their own account. Sign in with password and TOTP, then choose Link single sign-on on
/admin/account. - The provider's
suband issuer are stored on the signed-in account, and nowhere else. The audit log recordsauth.sso_linked. - The link request is bound to that session. Finished in another browser or after sign-out, it links nothing.
- An identity already linked to another account is refused. An unlinked identity cannot sign in.
- Unlink single sign-on removes the link (
auth.sso_unlinked). An account without a password cannot unlink its only way in. - The password keeps working. Every login still ends with TOTP, as for every account.