Uploaded image for project: 'OpenId Connect'
  1. OpenId Connect
  2. OIDC-118

It is possible to bypass OpenID login by providing a custom provider

    XMLWordPrintable

Details

    • Unit
    • Unknown

    Description

      Even if a wiki has an OpenID provider configured through its xwiki.properties, it is possible to provide a third party provider by providing its details through request parameters. One can then bypass the XWiki authentication altogether by specifying its own provider through the oidc.endpoint.* request parameters (or by using an XWiki-based OpenID provider with oidc.xwikiprovider.

      With the same approach, one could also provide a specific group mapping through oidc.groups.mapping that would make his user automatically part of the XWikiAdminGroup

      Attachments

        Activity

          People

            tmortagne Thomas Mortagne
            caubin Clément Aubin
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: