Fix plus-address sign-in and finish NK-WP-0041
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e31f-2bcc-7051-a050-70d8cb2dfa49
This commit is contained in:
parent
6700d8f995
commit
2f1e6c3369
7 changed files with 306 additions and 17 deletions
|
|
@ -121,10 +121,17 @@ data:
|
|||
# KeyCape is the only registered client.
|
||||
identity_providers:
|
||||
oidc:
|
||||
# Authelia 4.39 no longer includes profile claims in ID tokens by
|
||||
# default. KeyCape uses this verified claim for directory/MFA lookup;
|
||||
# its opaque OIDC subject is not a directory username (NK-WP-0041).
|
||||
claims_policies:
|
||||
keycape:
|
||||
id_token: [preferred_username]
|
||||
# hmac_secret: injected via AUTHELIA_IDENTITY_PROVIDERS_OIDC_HMAC_SECRET_FILE
|
||||
# issuer_private_key: injected via AUTHELIA_IDENTITY_PROVIDERS_OIDC_ISSUER_PRIVATE_KEY_FILE
|
||||
clients:
|
||||
- id: keycape
|
||||
claims_policy: keycape
|
||||
description: "KeyCape IAM Orchestration Layer"
|
||||
# OIDC clients are a list, so Authelia's *_FILE environment
|
||||
# mechanism cannot override this field. The template filter reads
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue