mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
Merge pull request #6727 from VJalili/oidc_consent
Updates to OIDC backends default config
This commit is contained in:
@@ -5,7 +5,7 @@
|
||||
<client_secret> ... </client_secret>
|
||||
<redirect_uri>http://localhost:8080/authnz/google/callback</redirect_uri>
|
||||
|
||||
<!-- <prompt>select_account</prompt> -->
|
||||
<prompt>consent</prompt>
|
||||
<!--The value of this parameter (i.e., prompt) specifies whether the Google authorization server should prompt
|
||||
a galaxy user for (re)authorization and consent. The possible values are: `none`, `consent`, and
|
||||
`select_account`. HOWEVER, DO NOT USE `none`, because it will cause authentication failure for new users.
|
||||
@@ -14,6 +14,12 @@
|
||||
|
||||
If you want the consent screen to be shown to the new users only, and re-authorization happen without
|
||||
asking for user's consent, then remove this attribute.
|
||||
|
||||
NOTE: Galaxy sets OIDC 'scope' (requested scope of access to user's account) to `openid`. This is the
|
||||
minimum scope value that request only user's email address and profile name. For login process Galaxy
|
||||
does not need any more information, hence we request minimum possible information. By design, Google
|
||||
does NOT show consent screen for this scope, hence user will only see a login page when they try to
|
||||
login to Galaxy using their Google account.
|
||||
-->
|
||||
</provider>
|
||||
</OIDC>
|
||||
|
||||
Reference in New Issue
Block a user