[OIDC] Auto-provision usernames from 'preferred_username' claim instead of 'name'

(#1238) Feature Under consideration security self-hosting

Problem

When a user is auto-provisioned via SSO their username is set to the 'name' claim resulting in usernames like 'John_Smith' instead of the more predominantly used 'preferred_username' like 'jsmith123' or 'bigbadjohn'. Users are able to change their username given they then set up a password within fluxer which is cumbersome and slightly defeats the seamlessness of auto-provisioned SSO login.

Proposal

Change the auto-provisioned username to use the 'preferred_username' OIDC claim instead of 'name' for uniformity and set the Display Name in fluxer to use the 'name' claim instead, which is much easier to change.

Merged posts

These posts were merged into this one. Their comments are now part of the conversation below, marked with where they came from.

Report details

Summary

When logging in and auto provisioning accounts with an SSO provider the account is created with a username matching a user's name and not the expected preferred_username claim. It is much easier to change a display name that may be off than the actual username of SSO created users as that requires a password to be set that these users, if auto-created, wouldn't have.

Steps to reproduce

Enabled SSO and setup a provider Enable auto-provision Enable require SSO Log in with a non existing fluxer user via SSO. Observe username is the SSO users actual name set in the SSO provider.

Environment

Self Hosted docker environment

6 comments

Sign in with Fluxer to comment and vote.
Comment by @Buco7854
RexSystem 1 vote Merged from #645 originally by @Buco7854 on GitHub
Just to let you know that while I agree that the username should use the prefered_username claim and the name the given_name (it seems to currently use it for both), users can actually set their password (and therefore change their username) even when SSO provisionned. If "require SSO" is not enabled they can even login with their email/password. Only thing that change is 2FA being bypassed by SSO.
Comment by @InsertDisc
RexSystem 1 vote Merged from #645 originally by @InsertDisc on GitHub OP
Just to let you know that while I agree that the username should use the prefered_username claim and the name the given_name (it seems to currently use it for both), users can actually set their password (and therefore change their username) even when SSO provisionned. If "require SSO" is not enabled they can even login with their email/password. Only thing that change is 2FA being bypassed by SSO.
I figured as much was possible. It's just out of the ordinary ya know.
Off-topic comment by @InsertDisc
RexSystem 1 vote Merged from #645 originally by @InsertDisc on GitHub OP Collapsed as outdated by Rex: Refers to closing the original GitHub issue.
This is more of a feature request than a bug. Closing.
Comment by @gmpinder
RexSystem 1 vote originally by @gmpinder on GitHub
I ran into the same issue when using authentik as my IDP. To work around this, I ended up creating a property mapping that set the name from the username on the claim. This made it so that Fluxer automatically got the correct username out of the gate.
Comment by @InsertDisc
RexSystem 1 vote originally by @InsertDisc on GitHub OP
That's a great workaround. I think I'll implement that as well. Thanks.
Comment by @TheGreenkey
RexSystem 1 vote originally by @TheGreenkey on GitHub
We ran into the same problem when first setting up fluxer. Generally we'd like to have claim mapping available as well. The current workaround works but then both the display name and username are the same...