Per-organisation OIDC #60

Closed
opened 2026-09-21 18:05:10 +01:00 by cruelacid · 1 comment
Owner

Part of #37. Pull forward on demand — the classic first-enterprise-deal unblocker.

What Relay does

Custom OIDC provider support (their issue #38, closed completed Jan 2026), sold
as SSO on Starter and above. Shipped as configuration: a generic provider
appears only if their control plane returns one, so SSO is a config change rather
than a rebuild. That is the shape to copy.

What we do today

Google, Microsoft and Apple, plus passkeys and email codes.
packages/identity/src/providers.ts:10 already wraps openid-client discovery —
but ProviderName is a closed union of three, so a fourth provider cannot be
added without a release.

What changes

A per-organisation OIDC configuration table, an admin UI to set it, and opening
the closed union so providers are data rather than code. The discovery machinery
is already there.

Risk

risk:additive. Identity service only; no sync path touched.

Verification

A test organisation against a real OIDC provider, and a check that one
organisation's configuration cannot be read or used by another — the tenant
isolation docs/launch-readiness.md Gate B already demands.

Part of #37. **Pull forward on demand** — the classic first-enterprise-deal unblocker. ## What Relay does Custom OIDC provider support (their issue #38, closed completed Jan 2026), sold as **SSO** on Starter and above. Shipped as configuration: a generic provider appears only if their control plane returns one, so SSO is a config change rather than a rebuild. That is the shape to copy. ## What we do today Google, Microsoft and Apple, plus passkeys and email codes. `packages/identity/src/providers.ts:10` already wraps `openid-client` discovery — but `ProviderName` is a **closed union of three**, so a fourth provider cannot be added without a release. ## What changes A per-organisation OIDC configuration table, an admin UI to set it, and opening the closed union so providers are data rather than code. The discovery machinery is already there. ## Risk `risk:additive`. Identity service only; no sync path touched. ## Verification A test organisation against a real OIDC provider, and a check that one organisation's configuration cannot be read or used by another — the tenant isolation `docs/launch-readiness.md` Gate B already demands.
Author
Owner

Moved to the Vikunja board as NEC-37: https://projectron.nerchure.com/tasks/37

Moved to the Vikunja board as **NEC-37**: https://projectron.nerchure.com/tasks/37
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#60
No description provided.