OIDC User being removed from Organisation
- Dominant language
- TypeScript
- Stars
- 22.8k
- Forks
- 783
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 53
Description
Added my Pocket ID admin user to Pangolin and set it to have the Admin role.
Open an incognito browser tab and connect to one of my proxied resources that is Uprotected in Pangolin and uses OIDC to auth directly with pocket touch. I am redirected to Pocket Touch, login and amsucesfully redirected to the resource.
I open another tab, and connect to a Protected resource, i get the Pangolin login page and choose the pocket id login option, i am already authed but am then told by Pangolin that i do not have access.
In my other browser logged into Pangolin as admin, i browse to users for the resource and find that my pocket id user no longer shows in the user list. If i go to Server Admin I can see the users in the list here.
Some mechanism in Pangolin is removing this user from the site.
Contributor guide
Assessment
This issue has not been assessed yet.