Per-organisation OIDC #60
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda#60
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Part of #37. Pull forward on demand — the classic first-enterprise-deal unblocker.
What Relay does
Custom OIDC provider support (their issue #38, closed completed Jan 2026), sold
as SSO on Starter and above. Shipped as configuration: a generic provider
appears only if their control plane returns one, so SSO is a config change rather
than a rebuild. That is the shape to copy.
What we do today
Google, Microsoft and Apple, plus passkeys and email codes.
packages/identity/src/providers.ts:10already wrapsopenid-clientdiscovery —but
ProviderNameis a closed union of three, so a fourth provider cannot beadded without a release.
What changes
A per-organisation OIDC configuration table, an admin UI to set it, and opening
the closed union so providers are data rather than code. The discovery machinery
is already there.
Risk
risk:additive. Identity service only; no sync path touched.Verification
A test organisation against a real OIDC provider, and a check that one
organisation's configuration cannot be read or used by another — the tenant
isolation
docs/launch-readiness.mdGate B already demands.Moved to the Vikunja board as NEC-37: https://projectron.nerchure.com/tasks/37