Add support for SSO on self-hosted instances

(#946) Feature Shipped security self-hosting

Problem

I would like to be able to have Single Sign On integration, like with Authelia, Authentik, etc.

Proposed solution

Add OIDC configuation, either through a config file, admin dashboard, or environment variables for docker usage. Whenever a user logs in through the SSO, and the user has not been created yet, a user is automatically created using the preferred_username claim, optionally pulling in the profile picture as well. One of these should probably happen too, preferably configurably:
  • When SSO is configured, disable the user registration and login that is built-in, and just redirect to the OIDC provider.
  • When SSO is configured, add a "Login with {SSO name}" button to the login page, and possibly disable user registration.

2 comments

Sign in with Fluxer to comment and vote.
Comment by @MrNavaStar
RexSystem 1 vote originally by @MrNavaStar on GitHub 1 reply
I would just like to add second voice asking for environment variables to configure OIDC settings. It makes things so much easier, especially when deploying services for high availability and reproducibility. I would also like to vote for automatic login flow instead of having to click a separate login button (assuming that regular login is disabled)
Comment by @NitroBrude
RexSystem 1 vote originally by @NitroBrude on GitHub
Chiming into say the same. I have a Discourse forum and allowing/forcing my users to login via those credentials would make this a a no-brainer for us over Sharkord, which seems to not be geared towards communities.