<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Apps with OpenID Connect Provider (beta)]]></title><description><![CDATA[<p dir="auto">Autodiscovery does not work and after manual entry of endpoints:</p>
<pre><code>ID token validate failed with error: Only RS256 signature validation is supported. Token reports using EdDSA
</code></pre>
<p dir="auto">Maybe this is the reason -&gt; <a href="https://github.com/BookStackApp/BookStack/issues/3206" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/BookStackApp/BookStack/issues/3206</a></p>
]]></description><link>https://forum.cloudron.io/topic/8940/apps-with-openid-connect-provider-beta</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Jul 2026 10:49:10 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/8940.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 02 Apr 2023 12:15:09 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Wed, 07 Jun 2023 15:47:49 GMT]]></title><description><![CDATA[<p dir="auto">I'm still struggling to properly set up openID with my applications. For example with Leantime I get <code>The received provider https://my.domain.tld/openid does not match the local setting https://my.domain.tld/.well-known/openid-configuration</code> after authentification. And ctfreak will complain that <code>redirect_uris for native clients using http as a protocol can only use loopback addresses as hostnames</code> and using https won't work.</p>
]]></description><link>https://forum.cloudron.io/post/67859</link><guid isPermaLink="true">https://forum.cloudron.io/post/67859</guid><dc:creator><![CDATA[andreasdueren]]></dc:creator><pubDate>Wed, 07 Jun 2023 15:47:49 GMT</pubDate></item><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Mon, 10 Apr 2023 11:22:41 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/luckow" aria-label="Profile: luckow">@<bdi>luckow</bdi></a> thanks, added it for next package release.</p>
]]></description><link>https://forum.cloudron.io/post/64667</link><guid isPermaLink="true">https://forum.cloudron.io/post/64667</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Mon, 10 Apr 2023 11:22:41 GMT</pubDate></item><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Mon, 10 Apr 2023 11:14:28 GMT]]></title><description><![CDATA[<p dir="auto">To test <a href="https://www.cloudron.io/store/org.apache.superset.cloudronapp.html" target="_blank" rel="noopener noreferrer nofollow ugc">Superset</a> with Oauth we need an additional library</p>
<pre><code>Apr 10 13:10:48 from authlib.integrations.flask_client import OAuth
Apr 10 13:10:48 ModuleNotFoundError: No module named 'authlib'
</code></pre>
<p dir="auto">Referring to <a href="https://superset.apache.org/docs/installation/configuring-superset/#custom-oauth2-configuration" target="_blank" rel="noopener noreferrer nofollow ugc">https://superset.apache.org/docs/installation/configuring-superset/#custom-oauth2-configuration</a></p>
]]></description><link>https://forum.cloudron.io/post/64665</link><guid isPermaLink="true">https://forum.cloudron.io/post/64665</guid><dc:creator><![CDATA[luckow]]></dc:creator><pubDate>Mon, 10 Apr 2023 11:14:28 GMT</pubDate></item><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Thu, 06 Apr 2023 12:21:52 GMT]]></title><description><![CDATA[<p dir="auto">I have removed the display of the secret now. Also 7.4.1 will support multiple redirectURIs with native app support. This was required for getting immich to work.</p>
<p dir="auto">Lets keep those issues coming so we can fix that up one-by-one</p>
]]></description><link>https://forum.cloudron.io/post/64503</link><guid isPermaLink="true">https://forum.cloudron.io/post/64503</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Thu, 06 Apr 2023 12:21:52 GMT</pubDate></item><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Tue, 04 Apr 2023 14:25:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> btw. we also have a UI glitch</p>
<p dir="auto"><img src="/assets/uploads/files/1680618314848-a6c23b94-3e42-414c-a359-6c4ee7e5a9e7-image.png" alt="a6c23b94-3e42-414c-a359-6c4ee7e5a9e7-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.cloudron.io/post/64337</link><guid isPermaLink="true">https://forum.cloudron.io/post/64337</guid><dc:creator><![CDATA[luckow]]></dc:creator><pubDate>Tue, 04 Apr 2023 14:25:40 GMT</pubDate></item><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Tue, 04 Apr 2023 13:45:01 GMT]]></title><description><![CDATA[<p dir="auto">Wrong forum section, I will move this to support as it is more like a generic OpenID thread now.</p>
<p dir="auto">I managed to get freescout working now with <a href="https://freescout.net/module/oauth-login/" target="_blank" rel="noopener noreferrer nofollow ugc">https://freescout.net/module/oauth-login/</a> and the added RS256 signature validation. We should be able to get this into 7.4.1</p>
]]></description><link>https://forum.cloudron.io/post/64335</link><guid isPermaLink="true">https://forum.cloudron.io/post/64335</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Tue, 04 Apr 2023 13:45:01 GMT</pubDate></item><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Tue, 04 Apr 2023 13:01:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/luckow" aria-label="Profile: luckow">@<bdi>luckow</bdi></a> Update: after going "back" to the Bookstack home page (with the sso login button) and clicking again (with a valid login on my oic provider), I get the error again:</p>
<pre><code>ID token validate failed with error: Only RS256 signature validation is supported. Token reports using EdDSA
</code></pre>
]]></description><link>https://forum.cloudron.io/post/64332</link><guid isPermaLink="true">https://forum.cloudron.io/post/64332</guid><dc:creator><![CDATA[luckow]]></dc:creator><pubDate>Tue, 04 Apr 2023 13:01:33 GMT</pubDate></item><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Tue, 04 Apr 2023 12:52:58 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> I followed<br />
<a href="https://www.bookstackapp.com/docs/admin/oidc-auth/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bookstackapp.com/docs/admin/oidc-auth/</a></p>
<p dir="auto">With <code>OIDC_ISSUER_DISCOVER=true</code> the error is</p>
<pre><code>OIDC Discovery Error: Unexpected issuer value found on discovery response
</code></pre>
<p dir="auto">With <code>OIDC_ISSUER_DISCOVER=false</code> the error is</p>
<pre><code>unrecognized route or not allowed method (GET on /interaction/uNAJ4bnbXdzrsVTA7pIl9/confirm)
</code></pre>
<p dir="auto">I have no idea, but maybe<br />
<code>OIDC_PUBLIC_KEY=https://my.example.org/openid/jwks</code> is wrong.<br />
The documentation says something with a .pem file:</p>
<pre><code># Path to identity provider token signing public RSA key
OIDC_PUBLIC_KEY=file:///keys/idp-public-key.pem
</code></pre>
]]></description><link>https://forum.cloudron.io/post/64331</link><guid isPermaLink="true">https://forum.cloudron.io/post/64331</guid><dc:creator><![CDATA[luckow]]></dc:creator><pubDate>Tue, 04 Apr 2023 12:52:58 GMT</pubDate></item><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Tue, 04 Apr 2023 12:03:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/luckow" aria-label="Profile: luckow">@<bdi>luckow</bdi></a> I have added RS256 now, but so far I haven't managed to get to the point to see the signature validation error. Can you spot something missing in my test env file:</p>
<pre><code>OIDC_NAME=Cloudron
OIDC_DISPLAY_NAME_CLAIMS=name
OIDC_CLIENT_ID=bookstackid
OIDC_CLIENT_SECRET=bookstacksecret
OIDC_ISSUER=https://nebulon.space
OIDC_ISSUER_DISCOVER=false
OIDC_AUTH_ENDPOINT=https://my.nebulon.space/openid/auth
OIDC_TOKEN_ENDPOINT=https://my.nebulon.space/openid/token
</code></pre>
<p dir="auto">The autodiscovery via .well-known also failed like you mentioned.</p>
]]></description><link>https://forum.cloudron.io/post/64329</link><guid isPermaLink="true">https://forum.cloudron.io/post/64329</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Tue, 04 Apr 2023 12:03:36 GMT</pubDate></item><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Sun, 02 Apr 2023 19:19:08 GMT]]></title><description><![CDATA[<p dir="auto">Yes we can support multiple ones <a href="https://github.com/panva/node-oidc-provider/blob/main/docs/README.md#jwks" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/panva/node-oidc-provider/blob/main/docs/README.md#jwks</a></p>
<p dir="auto">I went for the recommended format first. Some more info about key algorithms <a href="https://www.scottbrady91.com/jose/jwts-which-signing-algorithm-should-i-use" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.scottbrady91.com/jose/jwts-which-signing-algorithm-should-i-use</a></p>
]]></description><link>https://forum.cloudron.io/post/64206</link><guid isPermaLink="true">https://forum.cloudron.io/post/64206</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Sun, 02 Apr 2023 19:19:08 GMT</pubDate></item><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Sun, 02 Apr 2023 14:58:35 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> maybe the same problem with Freescout? <a href="https://freescout.net/module/saml/" target="_blank" rel="noopener noreferrer nofollow ugc">https://freescout.net/module/saml/</a></p>
<p dir="auto"><strong>Requirements</strong><br />
<code>Signature Algorithm is RSA-SHA256.</code></p>
]]></description><link>https://forum.cloudron.io/post/64175</link><guid isPermaLink="true">https://forum.cloudron.io/post/64175</guid><dc:creator><![CDATA[luckow]]></dc:creator><pubDate>Sun, 02 Apr 2023 14:58:35 GMT</pubDate></item><item><title><![CDATA[Reply to Apps with OpenID Connect Provider (beta) on Sun, 02 Apr 2023 14:50:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> Can we have mulitple key algos?</p>
]]></description><link>https://forum.cloudron.io/post/64170</link><guid isPermaLink="true">https://forum.cloudron.io/post/64170</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Sun, 02 Apr 2023 14:50:48 GMT</pubDate></item></channel></rss>