Repository navigation
docs(oidc): document fallback claim lists for acl.oidc.sub.claim and acl.oidc.groups.claim - #575
Open
glasstiger wants to merge 2 commits into
Open
glasstiger wants to merge 2 commits into
glasstiger wants to merge 2 commits into
Conversation
…acl.oidc.groups.claim acl.oidc.sub.claim and acl.oidc.groups.claim accept a comma-separated list of claim names in priority order (questdb/questdb-enterprise#1267). - OIDC guide: new "User and group claims" section covering fallback claim lists, the rules for missing, null and empty claims, the startup validation and the "Failed to find required claims" log message. - Entra ID guide: accepting managed identity and service principal (app-only) tokens alongside user logins. - Configuration reference: claim list syntax for both settings; acl.oidc.groups.claim has no default and is required with OIDC enabled. - Configuration reference: rename acl.oidc.pkce.enabled to acl.oidc.pkce.required, the name the server reads. - Changelog: October 2026 entries.
|
🚀 Build success! Latest successful preview: https://preview-575--questdb-documentation.netlify.app/docs/ Commit SHA: 4a5cba0
|
…setup - Require a single-tenant QuestDB app registration for app-role mapping: token mode checks the signature, aud and exp, but not the issuer or tenant - Add 4.0.2 warnings to the claims section, the Entra ID subsection and the configuration reference, including the pre-4.0.2 requirement for a groups array in token mode - Link the non-interactive clients section and the claim examples to the Entra ID subsection, and label the example payloads as Entra ID tokens - Cover app role assignment, managed identity token caching, the HTTP and INSERT grants, the token scope, and token refresh for services - Document token-mode validation (kid, aud, exp, non-empty sub) and its log messages under Rejected logins, and add sub to the app-only payload - Describe token mode as reading the JWT the client presents, not only the ID token
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Documents questdb/questdb-enterprise#1267:
acl.oidc.sub.claimandacl.oidc.groups.claimnow accept a comma-separated list of claim names in priority order, such asname,oid,subandgroups,roles.nulland empty claims fall through,nulland empty group names are skipped, groups are never combined across claims, only top-level claims count, names are case-sensitive, listed claims must have the expected shape, and unlisted claims are ignored whatever their shape;Failed to find required claims [subClaims=..., groupsClaims=...]log line for rejected logins.name,oid,sub/groups,rolesconfiguration;acl.oidc.groups.encoded.in.token=true, issue v2.0 access tokens (requestedAccessTokenVersion: 2) so thataudmatchesacl.oidc.audience, and give each identity at least one app role;CREATE GROUP ... WITH EXTERNAL ALIAS.acl.oidc.groups.claimnow shows no default, because it is required when OIDC is enabled (this was true before #1267 as well);acl.oidc.pkce.enabledrenamed toacl.oidc.pkce.required, the name the server reads, with a note that the old name is ignored.Dependencies
mainis4.0.2-SNAPSHOT. Adjust them if it lands in a different release.