Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[ask feature] ocis compatible with ocis client secret and service account #10927

Open
HoaMi opened this issue Jan 24, 2025 · 0 comments
Open

Comments

@HoaMi
Copy link

HoaMi commented Jan 24, 2025

Is your feature request related to a problem? Please describe.

Hello,

We use a keycloak as an external oidc.
To manage our ocis, we use python scripts that connect directly to our keycloak with user/password.
We have to configure the keycloak client with access grant enabled and pkce disabled, otherwise our scripts won't be able to connect to keycloak.
The problem is that this is a major vulnerability: A malicious person could make a phising app that calls our keycloak whatever he wants.

Describe the solution you'd like

Will it be possible for ocis to be compatible with an oidc secret client?
In order to be able to create a service account on keycloak

This would enable a more standard interconnection with keycloak.

Describe alternatives you've considered

Additional context

ocis version: 7.0.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant