handmade.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
handmade.social is for all handmade artisans to create accounts for their Etsy and other handmade business shops.

Server stats:

36
active users

#keycloak

0 posts0 participants0 posts today

If you ever try to get #Keycloak OAuth2 login working with #Odoo, and wonder why there are dozens of reported issues about "Sign up is not allowed on this database", here is the fix:

Go to /odoo/system-parameters and add a new parameter "auth_oauth.authorization_header" with value "True". It's infuriating I had to come to this conclusion by actively trying to fix the Python code, only to find out it doesn't need fixing but an undocumented config parameter.

Replied to Max Maass :donor:

@hacksilon Thanks for your response. Let me give you a bit more context on the issue I'm facing.

I installed OCIS (ownCloud Infinite Scale) and configured it to use Keycloak as the OIDC provider. The web login works perfectly, but I'm having trouble with the mobile apps (iOS and Android). Whenever I try to log in from the mobile apps, Keycloak reports a "client not found" error.

From what I've gathered from various forum posts, it seems that Keycloak is creating a new client each time a login attempt is made from the mobile apps. These dynamically created clients are not configured properly, which is causing the login to fail.

One developer suggested disabling dynamic client registration in Keycloak to prevent this issue. However, I'm not sure how to do this, especially since I'm using Keycloak version 26 and the settings aren't intuitive.

Your understanding that dynamic client registration is disabled by default makes sense, but it seems like something might be triggering it in my setup. Do you have any ideas on how I can ensure dynamic client registration is fully disabled, or any other suggestions to resolve this issue?

Thanks for your help!

Github: github.com/owncloud/client/iss

GitHubOCHTTPStatusErrorDomain because new generic KeyCloak Client is being created for each login from Desktop/iOS/Android · Issue #11940 · owncloud/clientBy walt-jones

hi #keycloak and/or #docker fans, I'm looking at the getting started instructions here, can anyone help me understand where keycloak would be storing its data if I follow this guide? keycloak.org/getting-started/g

I don't see any bind mounts and I'm sorta worried all my data will go poof when the container is destroyed next reboot

www.keycloak.orgDocker - KeycloakKeycloak is an open source identity and access management solution

Ive recently set up #SSO into my #kubernetes ingress layer using #traefik in my #homelab setup, and I have to say its going quite well.

Im using the keycloakopenid middleware and pointing it to my #keycloak instance.

I could then enable the middleware on all of my ingressRoutes, and traefik immediately redirects requests to the login page if a valid bearer token is not present in the request.

I had to carve out some exceptions so the keycloak admin panel is protected but the routes needed to login are still accessible anonymously.

It works well, without any fuss.

Next up I am hoping to configure the backend apps protected by this for better integration.

For example, #argoCD has SSO capabilities, and I should be able to enable them and not be promoted for a second login after the traefik layer login.

Long shot but, if there's any keycloak expert: sometimes the session for federated uses doesn't include email although it's in scope. Any idea where I should look to investigate and ideally fix the problem?
(I can't find anything on GitHub and Google, of course)

Je viens de publier un cours intitulé "Identité et méthodes d'authentification" sous licence CC-BY : broken-by-design.fr/posts/cour

Ce cours s'adresse aux personnes de niveau M2 et aux professionnel.les débutant.es, même si les plus expérimenté.es pourraient y trouver des informations intéressantes.

Il comprend une introduction aux différents types de référentiels d'identités, avant de plonger dans l'authentification, sous des angles juridiques et techniques. Authentification multifacteur, forte, résistante au phishing, assurant de bonnes garanties de vie privée ! Authentification à l'état de l'art ! Vous pourrez en apprendre plus à ces sujets grâce à ce cours.

Et ce n'est que la première partie ! Ce mois-ci, une seconde partie sera publiée, sur le sujet de l'autorisation, avec un TP de mise en place de #Keycloak pour une authentification fédérée avec OpenID Connect! À suivre !

broken-by-design.frIdentité et méthodes d'authentification | Broken by DesignUn cours de niveau M2 sur l'identité et les méthodes d'authentification

My #introduction (since I changed instance):

I am a Norwegian IT-engineer at the University of #Oslo. Originally from #Brazil, I moved to #Norway in 2011.

I work mostly with VMware stuff, but also spend most part of my days configuring #linux images for VDI's, #Nextcloud, #Kerberos, #FreeIPA, #keycloak, etc.

I love #running, #sourdough baking and became #vegan in Feb 2022. I have #glaucoma.

I started mastodon.babb.no for friends and colleagues.

Mastodon hosted on babb.noBabb.noThis Norwegian Mastodon server is an unofficial meeting place for University of Oslo people, and more!