Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Offical apps | Community apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Grist
  3. Grist 1.2.6 removing SSO via OIDC/SAML

Grist 1.2.6 removing SSO via OIDC/SAML

Scheduled Pinned Locked Moved Grist
3 Posts 2 Posters 96 Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • U
    U
    umnz
    wrote last edited by umnz
    #1

    "Update on OIDC/SAML support

    As of this release, Grist Labs will no longer be officially supporting SSO via OIDC/SAML outside of the full edition of Grist. If you're already running OIDC or SAML on a self-hosted Grist installation configured before this change, it should continue to work. If you're relying on OIDC/SAML in production, absolutely reach out to us, we want full Grist to work for your organization."

    Hello team,

    One of our Cloudron instances is using Grist without the Full Edition license (since the organization doesn't qualify). Grist found a niche as part of a few business processes where we needed a few users from different departments to be able to login and check the progress on some n8n workflows. Historically we had used n8n's data tables but they were severely limited and not intuitive - which is where the self hosted Grist-core with Custom Widgets became very useful.

    The question is whether or not we should be installing this update since our Grist instance is used in production and is part of our workflows (albeit, nothing insane) and our Cloudron users have been using SSO. And before anyone suggests it we're not going to just apply a full edition license and violate the terms.

    @James

    1 Reply Last reply
    0
    • jamesJ
      jamesJ
      james
      Staff
      wrote last edited by james
      #2

      Hello @umnz
      I would disable automatic updates for your production grist until this is resolved.
      Create a clone of the production grist and update the clone and validate the clone if everything is working.
      After that you should have a good idea of what to expect.

      Since they state:

      As of this release, Grist Labs will no longer be officially supporting SSO via OIDC/SAML outside of the full edition of Grist. If you're already running OIDC or SAML on a self-hosted Grist installation configured before this change, it should continue to work. If you're relying on OIDC/SAML in production, absolutely reach out to us, we want full Grist to work for your organization.

      The important part being:

      If you're already running OIDC or SAML on a self-hosted Grist installation configured before this change, it should continue to work.

      Should is the key word here.
      Meaning they can go break that (deliberately or not) in the future and just shrug it of with stating:

      Grist Labs no longer be officially supporting SSO via OIDC/SAML outside of the full edition of Grist

      So if I where in your position I would see to migrating the SSO users to normal users.
      If I remember correctly I did test that some time ago.
      When SSO users exist and try to login and there is no SSO support it shows a migration message for that user.

      But please test that with a cloned version and report what you find for everyone else.

      1 Reply Last reply
      2
      • U
        U
        umnz
        wrote last edited by
        #3

        We learned a while back not to allow auto updates, hence checking release notes before each update.

        I won't be able to do any testing until later this week unfortunately. If we have to, we'll migrate to normal users and then we'll likely look at moving to nocodb or similar. Can't be supporting enshittification.

        1 Reply Last reply
        1

        Hello! It looks like you're interested in this conversation, but you don't have an account yet.

        Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

        With your input, this post could be even better 💗

        Register Login
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Don't have an account? Register

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • Bookmarks
        • Search