Skip to content

Single sign-on (SSO)

eodia analytics accepts sign-in with a password and with OpenID Connect (Keycloak, Microsoft Entra ID, Google, Authentik… any provider that publishes a discovery configuration). A single provider is declared per instance, through environment variables. It is the same mechanism as in eodia insights: the same provider can serve both.

With the provider, register a web application with this redirect address:

https://stats.example.com/api/auth/oidc/callback

It is derived from PUBLIC_URL: check that this variable gives the public address of the instance. Then, on the eodia analytics side:

Fenêtre de terminal
OIDC_ISSUER=https://sso.example.com/realms/entreprise
OIDC_CLIENT_ID=eodia-analytics
OIDC_CLIENT_SECRET=…
OIDC_LABEL="Sign in with your company account"

Sign-in follows the authorization code flow with PKCE. The ID token is verified with the keys published by the provider (issuer, audience, nonce).

The first time a person signs in:

  • if their OIDC identity is already linked to an account, they sign in to it;
  • otherwise, if an account has the same email address, the identity is linked to it;
  • otherwise, an account is created, with the address and name sent by the provider.

The provider must therefore send an email address (email). An account deactivated in Administration › People can no longer sign in, even through SSO.

Fenêtre de terminal
OIDC_GROUPS_CLAIM=groups

With this variable, the provider’s groups are mirrored at each sign-in: the person is removed from their custom groups, then added to those whose name appears in the claim. The groups must exist in eodia analytics with the same name; those that do not exist are ignored.

Access to sites is granted per group, in each site’s Settings: read access (installation, verification, statistics) or edit access (settings, metadata). Administrators see everything; creating a site is reserved for them.

Fenêtre de terminal
PASSWORD_LOGIN=0

The sign-in screen then offers only the provider’s button, and the API rejects any password sign-in. On a new instance, the screen for creating the first administrator is still offered: give it the email address of their account with the provider, since they will then sign in through SSO and their account will be found by that address.

Administration › Settings shows whether SSO and email sending are configured.

eodia analytics is free software by Eodia.