Skip to content

[Initiative] Enterprise SSO Support #47

Description

@juliuskrah

Summary

Enable enterprise Single Sign-On (SSO) for GitStore using standards-based federation with external identity providers.

Scope

In scope:

  • OIDC federation support for enterprise IdPs.
  • SAML federation support through a supported broker/provider integration path.
  • Mapping IdP claims (groups, roles) to GitStore scopes and roles.
  • Tenant-specific identity configuration for enterprise deployments.
  • End-to-end authentication flow tests for enterprise login paths.

Out of scope:

Acceptance Criteria

  • Enterprise users can authenticate with external IdPs through configured SSO.
  • Claims-to-scope mapping is documented and enforced in API authorization.
  • Failure paths (issuer mismatch, invalid audience, expired token) are tested.
  • Documentation includes setup examples for at least one OIDC provider and one SAML provider.

Dependencies

Tracking

  • Milestone: TBD

Metadata

Metadata

Assignees

No one assigned
    No fields configured for Feature.

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions