PhilanthropyDataCommons / auth

PDC related extensions that were made for the keycloak auth service
1 stars 1 forks source link

keycloak identity providers handling and considerations #36

Open jmergy opened 3 weeks ago

jmergy commented 3 weeks ago

@kfogel @bickelj I could see the need/want to just leverage the keycloak identity providers as we ramp on end users into the next phases of the work and the apps leveraging the auth vs. creation of direct users in keycloak. Just creating this to raise any concerns on what provisioning does that way vs. direct users as it relates to roles, permissions, etc. in PDC.

jmergy commented 3 weeks ago

image

bickelj commented 2 days ago

With today's upgrade to Keycloak 26, a new feature is available: Organizations.

I think that feature should help us do all the things we need to do. See also https://github.com/PhilanthropyDataCommons/service/issues/1291

bickelj commented 2 days ago

@jmergy Would you be willing to try it with your organization and its authentication to explore? I can create the organization, set the domain, etc. We might have to change email addresses or something on existing users to better experiment, but I think it should be fairly straightforward.

jmergy commented 2 days ago

Sure. Don't want to add more you the plate here but I do think it will help adoption later.

jmergy commented 2 days ago

I can take on testing with the ones I know we will be hit with in MS and Google.