OIDC integration

With OIDC on, the identity provider is a second way past the first factor. It never replaces the second factor.

  • Login uses PKCE; the app checks the provider's signed ID token (see OIDC_SERVER_METADATA_URL in the configuration table).
  • Each person links their own account. Sign in with password and TOTP, then choose Link single sign-on on /admin/account.
  • The provider's sub and issuer are stored on the signed-in account, and nowhere else. The audit log records auth.sso_linked.
  • The link request is bound to that session. Finished in another browser or after sign-out, it links nothing.
  • An identity already linked to another account is refused. An unlinked identity cannot sign in.
  • Unlink single sign-on removes the link (auth.sso_unlinked). An account without a password cannot unlink its only way in.
  • The password keeps working. Every login still ends with TOTP, as for every account.

Edit this page on GitHub