Skip to content

Redirect to default IDP if user is not linked #370

Answered by sventorben
mm-pcosco asked this question in Q&A
Discussion options

You must be logged in to vote

Ok, I see. You want to redirect non-existend users to an identity provider while existing local users should be able to enter their password, right?

That is currently not supported.

If this were supported by the extension, it would make it easy for attackers to discover registered emails present on keycloak, because the attacker would see different behaviour for non-existent and existent accounts.

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@mm-pcosco
Comment options

@sventorben
Comment options

Answer selected by mm-pcosco
@mm-pcosco
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants