Skip to content

docs: OIDC UserInfo claims and identity-based account matching - #160

Merged
gantoine merged 1 commit into
mainfrom
docs/oidc-userinfo-identity
Sep 30, 2026
Merged

gantoine merged 1 commit into
mainfrom
docs/oidc-userinfo-identity

Conversation

@gantoine

Copy link
Copy Markdown
Member

Documents two OIDC login changes in rommapp/romm:

Changes:

  • OIDC Setup: "How it works" mentions the UserInfo fallback; new Account matching section; the "Email must match" note and the role-claim hints now cover the UserInfo response.
  • Authentication Troubleshooting: the role-claim check covers UserInfo, "Email is missing from token" is no longer Zitadel-only, and a new entry covers the 403 with the SQL to clear a stale link.
  • Zitadel and Authelia guides: the lines that said email is the only link between accounts.

Hold this until both romm PRs merge (#4892 is stacked on #4893).

trunk check is clean. mkdocs build --strict shows only the local cairosvg social-card warning.

AI assistance: written by Claude Code, with the maintainer reviewing.

🤖 Generated with Claude Code

Document that claims missing from the ID token come from the UserInfo
endpoint, and that accounts link to the provider's issuer and subject
after their first email match, with the 403 for a reassigned email.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gantoine
gantoine merged commit 7c52090 into main Sep 30, 2026
4 checks passed
@gantoine
gantoine deleted the docs/oidc-userinfo-identity branch September 30, 2026 00:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant