Skip to content

Commit 3ba1f74

Browse files
RHIDP-6882 - RHBK authentication: set the sub claim OIDC resolver as default (#1111)
Co-authored-by: Fabrice Flore-Thébault <[email protected]>
1 parent b8c0480 commit 3ba1f74

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed

modules/authentication/proc-enabling-authentication-with-rhbk.adoc

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -147,18 +147,21 @@ auth:
147147

148148
`signIn`::
149149
`resolvers`:::
150-
After successful authentication, the user signing in must be resolved to an existing user in the {product-short} catalog. To best match users securely for your use case, consider configuring a specific resolver. Enter the resolver list to override the default resolver: `emailLocalPartMatchingUserEntityName`.
150+
After successful authentication, the user signing in must be resolved to an existing user in the {product-short} catalog.
151+
To best match users securely for your use case, consider configuring a specific resolver.
152+
Enter the resolver list to override the default resolver: `oidcSubClaimMatchingKeycloakUserId`.
151153
+
152154
The authentication provider tries each sign-in resolver in order until it succeeds, and fails if none succeed.
153155
+
154156
WARNING: In production mode, only configure one resolver to ensure users are securely matched.
155157
`resolver`::::
156158
Enter the sign-in resolver name.
157159
Available values:
160+
* `oidcSubClaimMatchingKeycloakUserId`
158161
* `emailLocalPartMatchingUserEntityName`
159162
* `emailMatchingUserEntityProfileEmail`
160163
* `preferredUsernameMatchingUserEntityName`
161-
164+
+
162165
.`{my-app-config-file}` fragment with optional `resolvers` list
163166
[source,yaml]
164167
----
@@ -168,6 +171,7 @@ auth:
168171
production:
169172
signIn:
170173
resolvers:
174+
- resolver: oidcSubClaimMatchingKeycloakUserId
171175
- resolver: preferredUsernameMatchingUserEntityName
172176
- resolver: emailMatchingUserEntityProfileEmail
173177
- resolver: emailLocalPartMatchingUserEntityName
@@ -191,7 +195,7 @@ auth:
191195
clientSecret: ${AUTH_OIDC_CLIENT_SECRET}
192196
signIn:
193197
resolvers:
194-
- resolver: emailLocalPartMatchingUserEntityName
198+
- resolver: oidcSubClaimMatchingKeycloakUserID
195199
dangerouslyAllowSignInWithoutUserInCatalog: true
196200
signInPage: oidc
197201
----

0 commit comments

Comments
 (0)