Ask Questions and Find Answers
Important:
Ask is now read-only. You can review any existing questions and answers, but not add anything new.
But - don't panic! While ask is no more, we've replaced it with discuss - the new Liferay Discussion Forum! Read more here here or just visit the site here:
discuss.liferay.com
Open ID Connect providers in virtual instance scope
Dear Liferayers
My current Liferay project involves several virtual instances and I have just realized that Open ID Connect providers are defined at System settings scope and these providers are shared among all the virtual instances (if OIDC enabled).
Does it make any sense? I agree that if each has its own OIDC server properly configured for its own domain name and redirects, cross-logins will not happen among the instances but IMHO , the users of a given instance should not even see a reference o other OIDC services apart from the one related to my instance.
What's you opinion?
Best Regards
Meanwhile I think I will have to hook the login portlet to make it just show the OIDC services belonging to each instance (hardcoding this somewhere)
My current Liferay project involves several virtual instances and I have just realized that Open ID Connect providers are defined at System settings scope and these providers are shared among all the virtual instances (if OIDC enabled).
Does it make any sense? I agree that if each has its own OIDC server properly configured for its own domain name and redirects, cross-logins will not happen among the instances but IMHO , the users of a given instance should not even see a reference o other OIDC services apart from the one related to my instance.
What's you opinion?
Best Regards
Meanwhile I think I will have to hook the login portlet to make it just show the OIDC services belonging to each instance (hardcoding this somewhere)
hi Aritz,
we are currently reviewing the configuration options for all of our more relevant SSO connectors and OAuth2. So this will probably be included soon.
Thanks.
Carlos.
we are currently reviewing the configuration options for all of our more relevant SSO connectors and OAuth2. So this will probably be included soon.
Thanks.
Carlos.
Copyright © 2025 Liferay, Inc
• Privacy Policy
Powered by Liferay™