Skip to content

Commit 91607e6

Browse files
authored
RHIDP-6882 - RHBK authentication: set the sub claim OIDC resolver as default (#1105)
1 parent 30b8879 commit 91607e6

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed

modules/authentication/proc-enabling-authentication-with-rhbk.adoc

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -147,7 +147,9 @@ auth:
147147

148148
`signIn`::
149149
`resolvers`:::
150-
After successful authentication, the user signing in must be resolved to an existing user in the {product-short} catalog. To best match users securely for your use case, consider configuring a specific resolver. Enter the resolver list to override the default resolver: `emailLocalPartMatchingUserEntityName`.
150+
After successful authentication, the user signing in must be resolved to an existing user in the {product-short} catalog.
151+
To best match users securely for your use case, consider configuring a specific resolver.
152+
Enter the resolver list to override the default resolver: `oidcSubClaimMatchingKeycloakUserId`.
151153
+
152154
The authentication provider tries each sign-in resolver in order until it succeeds, and fails if none succeed.
153155
+
@@ -156,10 +158,11 @@ WARNING: In production mode, only configure one resolver to ensure users are sec
156158
`resolver`::::
157159
Enter the sign-in resolver name.
158160
Available values:
161+
* `oidcSubClaimMatchingKeycloakUserId`
159162
* `emailLocalPartMatchingUserEntityName`
160163
* `emailMatchingUserEntityProfileEmail`
161164
* `preferredUsernameMatchingUserEntityName`
162-
165+
+
163166
.`{my-app-config-file}` fragment with optional `resolvers` list
164167
[source,yaml]
165168
----
@@ -169,6 +172,7 @@ auth:
169172
production:
170173
signIn:
171174
resolvers:
175+
- resolver: oidcSubClaimMatchingKeycloakUserId
172176
- resolver: preferredUsernameMatchingUserEntityName
173177
- resolver: emailMatchingUserEntityProfileEmail
174178
- resolver: emailLocalPartMatchingUserEntityName
@@ -192,7 +196,7 @@ auth:
192196
clientSecret: ${AUTH_OIDC_CLIENT_SECRET}
193197
signIn:
194198
resolvers:
195-
- resolver: emailLocalPartMatchingUserEntityName
199+
- resolver: oidcSubClaimMatchingKeycloakUserID
196200
dangerouslyAllowSignInWithoutUserInCatalog: true
197201
signInPage: oidc
198202
----

0 commit comments

Comments
 (0)