<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Grist 1.2.6 removing SSO via OIDC/SAML]]></title><description><![CDATA[<p dir="auto">"Update on OIDC/SAML support</p>
<p dir="auto">As of this release, Grist Labs will no longer be officially supporting SSO via OIDC/SAML outside of the full edition of Grist. If you're already running OIDC or SAML on a self-hosted Grist installation configured before this change, it should continue to work. If you're relying on OIDC/SAML in production, absolutely reach out to us, we want full Grist to work for your organization."</p>
<p dir="auto">Hello team,</p>
<p dir="auto">One of our Cloudron instances is using Grist without the Full Edition license (since the organization doesn't qualify). Grist found a niche as part of a few business processes where we needed a few users from different departments to be able to login and check the progress on some n8n workflows. Historically we had used n8n's data tables but they were severely limited and not intuitive - which is where the self hosted Grist-core with Custom Widgets became very useful.</p>
<p dir="auto">The question is whether or not we should be installing this update since our Grist instance is used in production and is part of our workflows (albeit, nothing insane) and our Cloudron users have been using SSO. And before anyone suggests it we're not going to just apply a full edition license and violate the terms.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/james" aria-label="Profile: James">@<bdi>James</bdi></a></p>
]]></description><link>https://forum.cloudron.io/topic/15880/grist-1.2.6-removing-sso-via-oidc-saml</link><generator>RSS for Node</generator><lastBuildDate>Mon, 21 Sep 2026 09:17:24 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/15880.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 31 Aug 2026 00:52:48 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Grist 1.2.6 removing SSO via OIDC/SAML on Thu, 17 Sep 2026 13:45:52 GMT]]></title><description><![CDATA[<p dir="auto"><a href="https://github.com/robchahin/sso-wall-of-shame/issues/738" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/robchahin/sso-wall-of-shame/issues/738</a></p>
]]></description><link>https://forum.cloudron.io/post/129600</link><guid isPermaLink="true">https://forum.cloudron.io/post/129600</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Thu, 17 Sep 2026 13:45:52 GMT</pubDate></item><item><title><![CDATA[Reply to Grist 1.2.6 removing SSO via OIDC/SAML on Thu, 17 Sep 2026 07:43:22 GMT]]></title><description><![CDATA[<p dir="auto">Hello <a class="plugin-mentions-user plugin-mentions-a" href="/user/umnz" aria-label="Profile: umnz">@<bdi>umnz</bdi></a></p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/umnz" aria-label="Profile: umnz">@<bdi>umnz</bdi></a> <a href="/post/129570">said</a>:</p>
<p dir="auto">Something weird with the code block in docs - it's: export <a href="mailto:GRIST_DEFAULT_EMAIL=admin@email.com" target="_blank" rel="noopener noreferrer nofollow ugc">GRIST_DEFAULT_EMAIL=admin@email.com</a></p>
</blockquote>
<p dir="auto">Thanks for pointing this out, fixing it.</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/umnz" aria-label="Profile: umnz">@<bdi>umnz</bdi></a> <a href="/post/129571">said</a>:</p>
<p dir="auto">Honestly, a completely enshittified experience. Anyone reading this.. don't bother with this app if you're starting out, it's only going to get worse.</p>
</blockquote>
<p dir="auto">That is honest feedback, but directed towards <a class="plugin-mentions-category plugin-mentions-a" href="/category/215/grist" aria-label="Profile: grist">@<bdi>grist</bdi></a> and not Cloudron.<br />
Unfortnuatly we have no control over what upstream apps decide.<br />
But that is also the reason why we started publishing more of our own apps like Cubby, Contacts, Mail and so on.</p>
]]></description><link>https://forum.cloudron.io/post/129572</link><guid isPermaLink="true">https://forum.cloudron.io/post/129572</guid><dc:creator><![CDATA[james]]></dc:creator><pubDate>Thu, 17 Sep 2026 07:43:22 GMT</pubDate></item><item><title><![CDATA[Reply to Grist 1.2.6 removing SSO via OIDC/SAML on Thu, 17 Sep 2026 02:21:35 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">So if I where in your position I would see to migrating the SSO users to normal users.<br />
If I remember correctly I did test that some time ago.<br />
When SSO users exist and try to login and there is no SSO support it shows a migration message for that user.</p>
</blockquote>
<p dir="auto"><img src="/assets/uploads/files/1789611274645-d49860ad-2c8c-4317-93cf-e752d69851e7-image-resized.jpeg" alt="image.jpeg" class=" img-fluid img-markdown" width="1564" height="1474" /></p>
<p dir="auto">We don't get the option to add a user manually it seems. When I try to "add user" in the top right profile menu, I get a redirect as the same user. I can't seem to create new users that way.</p>
<p dir="auto">When I try to invite to a document using the link, I get the Cloudron login page (if I'm using incognito, otherwise it just logs me in as me automatically).</p>
<p dir="auto"><img src="/assets/uploads/files/1789611588008-3d863c97-4d7f-4093-954a-88aa944a2bf0-image-resized.jpeg" alt="image.jpeg" class=" img-fluid img-markdown" width="1316" height="1326" /></p>
<p dir="auto">Honestly, a completely enshittified experience. Anyone reading this.. don't bother with this app if you're starting out, it's only going to get worse.</p>
]]></description><link>https://forum.cloudron.io/post/129571</link><guid isPermaLink="true">https://forum.cloudron.io/post/129571</guid><dc:creator><![CDATA[umnz]]></dc:creator><pubDate>Thu, 17 Sep 2026 02:21:35 GMT</pubDate></item><item><title><![CDATA[Reply to Grist 1.2.6 removing SSO via OIDC/SAML on Thu, 17 Sep 2026 02:10:14 GMT]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1789610835982-d13023b2-2d13-47b7-b1b2-617a5f8e98f8-image-resized.jpeg" alt="image.jpeg" class=" img-fluid img-markdown" width="2162" height="590" /></p>
<p dir="auto">Something weird with the code block in docs - it's: <code>export GRIST_DEFAULT_EMAIL=admin@email.com</code></p>
]]></description><link>https://forum.cloudron.io/post/129570</link><guid isPermaLink="true">https://forum.cloudron.io/post/129570</guid><dc:creator><![CDATA[umnz]]></dc:creator><pubDate>Thu, 17 Sep 2026 02:10:14 GMT</pubDate></item><item><title><![CDATA[Reply to Grist 1.2.6 removing SSO via OIDC/SAML on Thu, 17 Sep 2026 02:05:42 GMT]]></title><description><![CDATA[<p dir="auto">Nevermind - needed to check the docs:<br />
<a href="https://docs.cloudron.io/packages/grist/" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.cloudron.io/packages/grist/</a></p>
]]></description><link>https://forum.cloudron.io/post/129569</link><guid isPermaLink="true">https://forum.cloudron.io/post/129569</guid><dc:creator><![CDATA[umnz]]></dc:creator><pubDate>Thu, 17 Sep 2026 02:05:42 GMT</pubDate></item><item><title><![CDATA[Reply to Grist 1.2.6 removing SSO via OIDC/SAML on Thu, 17 Sep 2026 02:04:45 GMT]]></title><description><![CDATA[<p dir="auto">Existing installation upgraded without much issues but new installations are not working as expected. A fresh Grist installation doesn't include any onboarding or administrator account so you can't configure anything.</p>
]]></description><link>https://forum.cloudron.io/post/129568</link><guid isPermaLink="true">https://forum.cloudron.io/post/129568</guid><dc:creator><![CDATA[umnz]]></dc:creator><pubDate>Thu, 17 Sep 2026 02:04:45 GMT</pubDate></item><item><title><![CDATA[Reply to Grist 1.2.6 removing SSO via OIDC/SAML on Mon, 31 Aug 2026 17:09:33 GMT]]></title><description><![CDATA[<p dir="auto">We learned a while back not to allow auto updates, hence checking release notes before each update.</p>
<p dir="auto">I won't be able to do any testing until later this week unfortunately. If we have to, we'll migrate to normal users and then we'll likely look at moving to nocodb or similar. Can't be supporting enshittification.</p>
]]></description><link>https://forum.cloudron.io/post/128759</link><guid isPermaLink="true">https://forum.cloudron.io/post/128759</guid><dc:creator><![CDATA[umnz]]></dc:creator><pubDate>Mon, 31 Aug 2026 17:09:33 GMT</pubDate></item><item><title><![CDATA[Reply to Grist 1.2.6 removing SSO via OIDC/SAML on Mon, 31 Aug 2026 07:27:44 GMT]]></title><description><![CDATA[<p dir="auto">Hello <a class="plugin-mentions-user plugin-mentions-a" href="/user/umnz" aria-label="Profile: umnz">@<bdi>umnz</bdi></a><br />
I would disable automatic updates for your production grist until this is resolved.<br />
Create a clone of the production grist and update the clone and validate the clone if everything is working.<br />
After that you should have a good idea of what to expect.</p>
<p dir="auto">Since they state:</p>
<blockquote>
<p dir="auto">As of this release, Grist Labs will no longer be officially supporting SSO via OIDC/SAML outside of the full edition of Grist. If you're already running OIDC or SAML on a self-hosted Grist installation configured before this change, it should continue to work. If you're relying on OIDC/SAML in production, absolutely reach out to us, we want full Grist to work for your organization.</p>
</blockquote>
<p dir="auto">The important part being:</p>
<blockquote>
<p dir="auto">If you're already running OIDC or SAML on a self-hosted Grist installation configured before this change, it should continue to work.</p>
</blockquote>
<p dir="auto"><strong>Should</strong> is the key word here.<br />
Meaning they can go break that (deliberately or not) in the future and just shrug it of with stating:</p>
<blockquote>
<p dir="auto">Grist Labs no longer be officially supporting SSO via OIDC/SAML outside of the full edition of Grist</p>
</blockquote>
<p dir="auto">So if I where in your position I would see to migrating the SSO users to normal users.<br />
If I remember correctly I did test that some time ago.<br />
When SSO users exist and try to login and there is no SSO support it shows a migration message for that user.</p>
<p dir="auto">But please test that with a cloned version and report what you find for everyone else.</p>
]]></description><link>https://forum.cloudron.io/post/128722</link><guid isPermaLink="true">https://forum.cloudron.io/post/128722</guid><dc:creator><![CDATA[james]]></dc:creator><pubDate>Mon, 31 Aug 2026 07:27:44 GMT</pubDate></item></channel></rss>