Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • 3 Votes
    6 Posts
    74 Views
    nebulonN
    So I am not sure what pangolin really needs here, but I did some more testing and the mentioned claims are all included in the JWT in my tests already in the currently released Cloudron OIDC server. How did you see that those aren't included in your case as you mentioned? Are you even getting a valid JWT and can you decode that? How does that json object look after that? The token response should look something like: { "access_token": "OGpFA1siYNbAQiCahuvjUDkKgoRAi4cz00lysJC6jt9", "expires_in": 3600, "id_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6IjFrRF..........", "refresh_token": "IJpU-ULmWoEYmUJmd55HLQF7aVHPbZIzdmWHUYQ1vB0", "scope": "openid profile email", "token_type": "Bearer" } Which then decoded in my case holds: Payload (Claims) sub: "nebulon" family_name: "" given_name: "Firstname" locale: "de-DE" name: "Lastname" preferred_username: "nebulon" picture: "https://my.cloudron/api/v1/profile/avatar/uid-e6e4afd0-f677-45e3-8d61-4dd039c32a11.png" email: "nebulon@..." email_verified: true aud: "cid-b901ffe1294a0683aff450bb86d036b5" exp: 1765189670 (8.12.2025, 11:27:50) iat: 1765186070 (8.12.2025, 10:27:50) iss: "https://my.cloudron..../openid"
  • client is invalid on gitea instances

    Solved Support oidc
    3
    1
    1 Votes
    3 Posts
    33 Views
    SansGuidonS
    I also had similar issues as soon as I migrated to Cloudron 9.x and after a while or maybe after successful login attempts with an alternative auth flow, I had no longer any issues authenticating through OpenID. weird indeed but I have noticed similar complains about Cloudron 9 and OIDC in other threads.
  • 2 Votes
    4 Posts
    81 Views
    jamesJ
    Hello @scooke Glad I could explain/resolve this issue for you.
  • MinIO not working anymore after upgrade to Cloudron 9

    Solved Minio oidc restart loop jwk
    2
    1 Votes
    2 Posts
    73 Views
    M
    Ok nevermind, I found the corresponding update and it works again after updating to the next version.
  • Update 9 - OpenID Broken - VPS OVH

    Solved Support oidc locale
    9
    1 Votes
    9 Posts
    167 Views
    girishG
    @SDEInfo fixed with https://git.cloudron.io/platform/box/-/commit/e87d2e1218ce0e6d5a9ee89e57976e459b73c7d4
  • External Provider (OIDC / OAuth) - Google Workspace

    Unsolved Support oidc
    8
    1 Votes
    8 Posts
    1k Views
    jamesJ
    Hello @Lomeu Did you figure this out or is this still an issue?
  • Clearing OIDC... cookie? user? -- How to log in and out?

    Solved Support oidc
    4
    1 Votes
    4 Posts
    618 Views
    jadudmJ
    @jdaviescoates and @girish: Excellent. Thank you. I can work with this. Very much appreciated.
  • OpenID Connect Error on iOS

    Traccar oidc
    20
    0 Votes
    20 Posts
    3k Views
    H
    @james the developer has released v5.1.1 which is supposed to have fixed the issue, however I am still experiencing the same behavior when I try to sign into the iOS app using OpenID. Can you please test on your iPhone and advise if it is the same for you as well?
  • 1 Votes
    3 Posts
    539 Views
    Z
    Indeed they're back when they login with OIDC, thanks for the tips. This ticket can be closed I think.
  • Can't use OpenID login due to unknown certificate

    Solved Support oidc certificates
    6
    1
    1 Votes
    6 Posts
    455 Views
    J
    @Mamouti if you need (smallish) changes to the packages, feel free to submit MRs . All the packages are at https://git.cloudron.io/packages/
  • OpenID login page blank on Firefox

    Solved Support firefox openid oidc
    5
    1 Votes
    5 Posts
    336 Views
    J
    MetaMask the crypto wallet? Not sure why that could be causing problems, but maybe a question for the MetaMask people.
  • OIDC login broken with 8.1.0 update

    Solved Directus directus oidc client
    9
    1 Votes
    9 Posts
    939 Views
    M
    thanks @nebulon & @girish, this does indeed fix everything, appreciate it
  • 0 Votes
    6 Posts
    2k Views
    nebulonN
    In OpenID there is no well supported way to log out users from services which used the OpenID for authentication (in Cloudron case the apps). Those app have their own session and session handling. So there is mostly likely no way around this unless an app would start using OAuth2 access and refresh tokens (but implementation of that was spotty in the past which sparked OpenID connect in the first place) For a start if you logout of the dashboard, subsequent app logins (from a state where the app has no login session) then Cloudron will prompt you to login with a username. If that is not happening the Oidc session was still alive. The best way I found was to use container tabs in like firefox and probably other browsers, which maintain isolated sessions. This is also how I use other services like Digitalocean where we have multiple accounts with different roles.
  • OpendID Connect: openid/session/end endpoint

    Solved Support oidc
    2
    0 Votes
    2 Posts
    504 Views
    nebulonN
    Good catch, we have to fixup the docs here. The OpenID provider session logout, triggered by the app used to be there, but we found that no app supports this properly so it got removed. For nextcloud, we have some changes to soon enable OIDC login by default in the package, so may not be worth it to investigate just now in your case.
  • External Wordpress with Cloudron OIDC

    Solved Support oidc wordpress
    2
    0 Votes
    2 Posts
    670 Views
    D
    Oops nm I figured out the right Wordpress login url and redirect pattern to use
  • New login notification email - Turn off?

    Solved Support oidc notification
    4
    1 Votes
    4 Posts
    422 Views
    D
    Thank you @girish - Sounds promising. Looking forward to v8.
  • Cloudron OIDC & Alias-Domains

    Solved Support oidc
    3
    1
    2 Votes
    3 Posts
    1k Views
    nebulonN
    Will be fixed with next release: https://git.cloudron.io/cloudron/box/-/commit/ec7dabc1c72c2f34c3f3474bc4b3c903bb2d693d
  • 1 Votes
    6 Posts
    1k Views
    M
    I want my users to OIDC via Cloudron to Cloudflares App Launcher where I can put all avialiable softwares some are from cloudron others are just SAAS (cloudflare can do SAML for SAAS) [image: 1712858310234-screenshot-2024-04-11-at-19.57.11-resized.png] Cloudron => Cloudflare Launcher => AWS
  • Apps SSO

    Solved Support oidc sso
    13
    1 Votes
    13 Posts
    4k Views
    girishG
    @nebulon has fixed this now for the next release. The first login (from admin setup or via invite) of admin account and normal users now has an OIDC session automatically. This means that when you click the first OIDC app, you are logged in automatically.
  • 0 Votes
    2 Posts
    678 Views
    nebulonN
    Currently our OpenID provider does not issue any refresh_tokens yet. All clients created without the refresh_token grant type. For the moment it is only useful as an identity provider as such. But we will extend it further based on requirements. Will look into this for the coming releases.