Skip to content

docs(auth): add enterprise identity broker integration guide #679

Description

@XiaoSeS

Parent

Goal

Document the supported broker pattern for enterprise identity sources that SkillHub does not natively implement: Keycloak, authentik, or Dex validates LDAP/AD/SAML/Kerberos upstream and exposes one OIDC issuer to SkillHub.

Scope

  • Broker topology and responsibility boundary
  • Concrete Keycloak/authentik/Dex setup references using their official documentation
  • SkillHub Spring OAuth2/OIDC registration variables and redirect URI
  • Stable issuer/registration/subject rules and email assurance mapping
  • Claim contract, provisioning/link policy, TLS/secret/CSRF/logging checklist
  • Upgrade, rollback, troubleshooting, and validation checklist
  • Explicit SAML/Kerberos boundary: broker first; no native implementation in this PR

Acceptance

  • No runtime/API/database behavior changes
  • No generated docs edits
  • Configuration examples only use verified SkillHub fields and clearly mark broker-specific fields as upstream examples
  • Official reference links are listed and reachable
  • Includes a copy/paste-safe validation checklist with no real credentials
  • Add README navigation link

Target big-main; do not merge to main without explicit maintainer confirmation.

Metadata

Metadata

Assignees

No one assigned

    Labels

    effort/m中等改动,存在一定协同成本 / Medium change with noticeable coordination cost.priority/p2中优先级 / Medium priority triage bucket.risk/high涉及安全、鉴权、迁移或公共契约 / Touches security, auth, migrations, or public contracts.triage/needs-info需要补充更多信息后才能分流 / Issue needs more detail before it can be routed.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions