-
Notifications
You must be signed in to change notification settings - Fork 162
adr: Document OIDC client parameter discovery #2253
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
| @@ -0,0 +1,67 @@ | ||||||
| --- | ||||||
| title: "Discover OIDC Client configuration via WebFinger" | ||||||
| --- | ||||||
|
|
||||||
| * Status: pending | ||||||
| * Deciders: [@TheOneRing @kulmann @rhafer @dragotin] | ||||||
| * Date: 2026-02-02 | ||||||
|
|
||||||
| Reference: https://github.com/opencloud-eu/opencloud/pull/2072, https://github.com/opencloud-eu/desktop/issues/217 | ||||||
|
|
||||||
| ## Context and Problem Statement | ||||||
|
|
||||||
| Up to now our client applications used hard-coded OIDC client configurations. | ||||||
| So it is not possible to change the client id that a client should use or the | ||||||
| list of scopes that a client needs to request. This makes it hard to integrate | ||||||
| OpenCloud with various existing identity providers. For example: | ||||||
|
|
||||||
| - Authentik basically creates a different issuer URL for each client. As OpenCloud | ||||||
| can only work with a single issuer URL, all OpenCloud clients need to use the | ||||||
| same client id to work with Authetnik. | ||||||
| - Some IDPs (kanidm) are not able to work with user-supplied client ids. They generate | ||||||
| client ids automatically and do not allow to specify them manually. | ||||||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. So how does OpenCloud get the information which client id to propagate to e.g. the Android app then?
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This will be a Server configuration variable |
||||||
| - To make features like automatic role assignment work, clients need to request | ||||||
| specific scopes, depending on which exact IDP is used. | ||||||
|
|
||||||
| ## Decision Drivers | ||||||
|
|
||||||
| * Support broader set of IDPs | ||||||
| * Do required the user got configure anything additional on the client side | ||||||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I don't understand this sentence 🙈
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Me neither 😄 |
||||||
|
|
||||||
| ## Decision | ||||||
|
|
||||||
| Enhance the WebFinger service in OpenCloud to provide platform-specific OIDC | ||||||
| discovery, enabling clients to query for the correct OIDC `client_id` and | ||||||
| `scopes` based on their application type (e.g., web, desktop, android, ios). | ||||||
|
|
||||||
| This is achieved by allowing and additional `platform` query parameter to be used | ||||||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||
| when querying the WebFinger endpoint. The response will include the appropriate | ||||||
| `client_id` and `scopes` in the `properties` section of the response. | ||||||
|
|
||||||
| This is implemented in a backward-compatible way, so existing clients that do not | ||||||
| specify the `platform` parameter will continue to receive just the issuer information. | ||||||
|
|
||||||
| ## Example | ||||||
|
|
||||||
| ### Client Request | ||||||
|
|
||||||
| ``` | ||||||
| GET /.well-known/webfinger?resource=https://cloud.opencloud.test&rel=http://openid.net/specs/connect/1.0/issuer&platform=desktop | ||||||
| ``` | ||||||
|
|
||||||
| ### Example Response | ||||||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||
|
|
||||||
| ```json | ||||||
| { | ||||||
| "subject": "https://cloud.opencloud.test", | ||||||
| "links": [{ | ||||||
| "rel": "http://openid.net/specs/connect/1.0/issuer", | ||||||
| "href": "https://idp.example.com" | ||||||
| }], | ||||||
| "properties": { | ||||||
| "http://opencloud.eu/ns/oidc/client_id": "desktop-client-id", | ||||||
| "http://opencloud.eu/ns/oidc/scopes": ["openid", "profile", "email", "offline_access"] | ||||||
| } | ||||||
| } | ||||||
| ``` | ||||||
|
|
||||||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. How would the server configuration for this look like? Especially since every platform might differ slightly. |
||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.