Skip to content

Conversation

@rhafer
Copy link
Contributor

@rhafer rhafer commented Feb 2, 2026

This basically documents what as discussed in #2072 and https://github.com/opencloud-eu/internal/issues/172

I am mainly adding to this to keep a record of why we're doing it and how.

@kulmann To make all clients use the same mechanism for discovering the oidc parameter it would IMO be good if web could switch to as well. However, looking at the other OIDC related parameters that can be configured in web. I have some questions.

  • WEB_OIDC_METADATA_URL: This allows to set the URL for the .well-known/openid-configuration endpoint. Do we really need that? This should always be the issuer-url as returned in the http://openid.net/specs/connect/1.0/issuer relation + .well-known/openid-configuration. The OIDC spec even define is as a MUST (https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfig).
  • ResponseType: We default to code here, have we ever encountered the need to set something else? To we need to have this configurable?
  • PostLogoutRedirectURI: I guess this is really specifc to web? So we should probably keep it in the config.json

@rhafer rhafer self-assigned this Feb 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant