jbreuer / Umbraco-OpenIdConnect-Example

An example to show how Umbraco and OpenIdConnect work together
MIT License
29 stars 9 forks source link

OpenIdConnect login only for existing members? #9

Open inetzo opened 5 months ago

inetzo commented 5 months ago

Hi @jbreuer ,

Thank you very much for this repro, it helped me a lot! However, I still have the following problem: I want members to be able to log in via OpenIdConnect, but only if the member already exists within Umbraco. The members are created manually. I had hoped that setting autoLinkExternalAccount = false would be sufficient, but then the message appears that there is no link.

Is it possible to use the login functionality of OpenIdConnect, but only for existing members?

Best regards,

iNETZO

dutchbreeze commented 5 months ago

Hi iNetzo,

We did/do a manual check for something similar on the OnTickedReceivedEvent. The member is then rather authenticated by the external provider, but can be denied if not exists on your local check. We use the principal to get the authenticated email address (claim) and compare this to allowed users (members in your case) using the member/user service.

Best regards,

Guido