-
Notifications
You must be signed in to change notification settings - Fork 1
/
maicol07-oidc-client.yml
63 lines (57 loc) · 2.83 KB
/
maicol07-oidc-client.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
maicol07-oidc-client:
admin:
settings:
client:
title: Client settings
subtitle: >
Add here your client details given by your OpenID Connect provider.
For further help, check the docs.
id: Client ID
secret: Client secret
enable_pkce: Enable PKCE (recommended)
enable_nonce: Enable nonce verification (recommended)
http_proxy: HTTP proxy
cert_path: Certificate path (in case of self-signed certificate)
verify_ssl: Verify SSL during requests
timeout: Requests timeout
allow_implicit_flow: Use implicit flow (not recommended)
skip_email_verified_check: Skip email verified claim check (useful for non-compliant providers that don't provide this claim, i.e. Casdoor)
callback_title: Callback URIs
callback_subtitle: These are the callback URIs you need to register on your provider to get the client authorization code and to logout from provider as well, if the related option has been enabled.
callback_logout_note: needed only when logging out from provider option is enabled (see at the bottom of the page)
provider:
title: Provider settings
subtitle: >
Add here your provider details.
If your provider uses autodiscovery you're not required to add the endpoints and some other fields (you're free to override them if you want!).
If your provider doesn't have implemented it yet, you can add the required settings manually below. Check the docs for further help
url: Provider URL
endpoints:
authorize: Authorization endpoint URL
token: Token endpoint URL
userinfo: Userinfo endpoint URL
logout: End session (logout) endpoint URL
jwks: JWKS endpoint URL
issuer: Issuer URL
code_challenge_method: Code challenge method
response_type: Response type of provider to authorization
id_token_signing_alg: ID token signing algorithm
authorization_response_iss_parameter_supported: Authorization response iss parameter supported
token_endpoint_auth_method: Token endpoint auth method
other:
title: Other settings
provider_name: Name of the provider to display on OIDC-related buttons
linker_claim: Linker claim
manage_account_url: Account management URL
manage_account_btn_open_in_new_tab: Open the account management page in a new tab
sso_mode: SSO mode
logout_from_provider: Logout from provider (when SSO mode is enabled)
remove_signup_btn: Remove signup button
sync_avatars: Sync user avatar
time_drift: JWT Time drift
forum:
buttons:
manage_account: Manage account
login: Login to {name}
connect_account: Connect to {name}
disconnect_account: Disconnect from {name}