<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Issue 1: Add SSO to roadmap - Bimba roadmap</title>
  <link rel="alternate" type="text/html" href="/issues/issue1" />
  <link href="https://roadmap.apiote.xyz/issues/issue1?%40template=item.xml" rel="self" />
  <updated>2025-04-26T12:12:20+00:00</updated>
  <id>https://roadmap.apiote.xyz/issues/issue1</id>
  
  <entry>
    <title>Message 34</title>
    <id>https://roadmap.apiote.xyz/issues/issue1#msg34</id>
    <content>
      
      <pre class="msg">Testing if mail-gw still works after enabling SSO</pre>
      
    </content>
    <published>2025-04-26T12:07:51+00:00</published>
    <updated>2025-04-26T12:07:51+00:00</updated>
    <author>
      <name>adam</name>
    </author>
  </entry>
  
  <entry>
    <title>Message 33</title>
    <id>https://roadmap.apiote.xyz/issues/issue1#msg33</id>
    <content>
      
      <pre class="msg">Applied on roadmap. Check email-gw. Logout doesn't redirect back</pre>
      
    </content>
    <published>2025-04-26T09:49:00+00:00</published>
    <updated>2025-04-26T09:49:00+00:00</updated>
    <author>
      <name>adam</name>
    </author>
  </entry>
  
  <entry>
    <title>Message 30</title>
    <id>https://roadmap.apiote.xyz/issues/issue1#msg30</id>
    <content>
      
      <div class="msg"><p>Left to do:
* apply on roadmap.apiote.xyz
* check mail gateway</p>
</div>
      
    </content>
    <published>2025-04-22T17:46:42+00:00</published>
    <updated>2025-04-22T17:46:42+00:00</updated>
    <author>
      <name>adam</name>
    </author>
  </entry>
  
  <entry>
    <title>Message 29</title>
    <id>https://roadmap.apiote.xyz/issues/issue1#msg29</id>
    <content>
      
      <pre class="msg">Left to do:
* check copying user data after login
* replace form with button
* check email gateway</pre>
      
    </content>
    <published>2025-04-15T08:01:47+00:00</published>
    <updated>2025-04-15T08:01:47+00:00</updated>
    <author>
      <name>adam</name>
    </author>
  </entry>
  
  <entry>
    <title>Message 28</title>
    <id>https://roadmap.apiote.xyz/issues/issue1#msg28</id>
    <content>
      
      <div class="msg"><p>change roles everywhere (including roadmap) to without ‘seat’</p>

<p>i.e.
* platform
* back
* window
* …</p>
</div>
      
    </content>
    <published>2025-04-12T16:01:58+00:00</published>
    <updated>2025-04-12T16:01:58+00:00</updated>
    <author>
      <name>adam</name>
    </author>
  </entry>
  
  <entry>
    <title>Message 15</title>
    <id>https://roadmap.apiote.xyz/issues/issue1#msg15</id>
    <content>
      
      <div class="msg"><ul>
<li><a rel="nofollow" href="https://auth0.com/docs/get-started/authentication-and-authorization-flow/resource-owner-password-flow">https://auth0.com/docs/get-started/authentication-and-authorization-flow/resource-owner-password-flow</a></li>
<li><a rel="nofollow" href="https://auth0.com/docs/secure/multi-factor-authentication/authenticate-using-ropg-flow-with-mfa">https://auth0.com/docs/secure/multi-factor-authentication/authenticate-using-ropg-flow-with-mfa</a></li>
</ul>
</div>
      
    </content>
    <published>2025-04-04T11:45:37+00:00</published>
    <updated>2025-04-04T11:45:37+00:00</updated>
    <author>
      <name>adam</name>
    </author>
  </entry>
  
  <entry>
    <title>Message 6</title>
    <id>https://roadmap.apiote.xyz/issues/issue1#msg6</id>
    <content>
      
      <div class="msg"><p>also: <a rel="nofollow" href="https://wiki.roundup-tracker.org/OauthAuthentication">https://wiki.roundup-tracker.org/OauthAuthentication</a></p>

<p>I think there are two main ways:
* simple but possibly insecure;
    * replace login form in roadmap with login button redirecting to SSO
    * add hook on SSO register to add user to roadmap and dummy password generated/stored in vault
    * pass user:specificPassword in authorization header to roadmap
* difficult:
    * integrate OIDC into login procedure in roadmap (cf. wiki link)</p>

<p>maybe it can be done in steps: first the simple step, then pass token to roadmap and check OIDC claims in login procedure (still needs users created in hook from SSO, with no password this time and safeguard not to check local password)</p>
</div>
      
    </content>
    <published>2025-03-18T11:15:17+00:00</published>
    <updated>2025-03-18T11:15:17+00:00</updated>
    <author>
      <name>adam</name>
    </author>
  </entry>
  
  <entry>
    <title>Message 1</title>
    <id>https://roadmap.apiote.xyz/issues/issue1#msg1</id>
    <content>
      
      <pre class="msg">* <a href="https://wiki.roundup-tracker.org/ShibbolethLogin" rel="nofollow noopener">https://wiki.roundup-tracker.org/ShibbolethLogin</a>
* <a href="https://wiki.roundup-tracker.org/LDAPLogin" rel="nofollow noopener">https://wiki.roundup-tracker.org/LDAPLogin</a>
* <a href="https://wiki.roundup-tracker.org/CustomisationExamples" rel="nofollow noopener">https://wiki.roundup-tracker.org/CustomisationExamples</a> #Security</pre>
      
    </content>
    <published>2025-03-02T13:15:24+00:00</published>
    <updated>2025-03-02T13:15:24+00:00</updated>
    <author>
      <name>adam</name>
    </author>
  </entry>
  
</feed>