AuthentificationRisque et fédération

Nœuds : Social Login / OIDC

Connexion via un provider social OAuth2/OIDC, dans le cadre d’un graphe d’authentification.

Graphe d'exemple : connexion sociale Google en OpenID Connect Graphe d'exemple : connexion sociale Google en OpenID Connect
Exemple : connexion Google. Redirection (1), échange du code (2), contrôle de l’e-mail vérifié (3), puis liaison au compte existant (4) ou création du compte (5).

SelectSocialProviderNode : affiche le choix du provider social.

Faites défiler le tableau
PropriétéTypeDéfaut
providersstring (obligatoire)Aucun
promptstringSelect identity provider

Outcome : outcome.

OidcRedirectNode : démarre un Authorization Code Flow avec PKCE (S256).

Faites défiler le tableau
PropriétéTypeDéfaut
clientIdstring (obligatoire)Aucun
authorizationEndpointstring (obligatoire)Aucun
redirectUristring (obligatoire)Aucun
scopesstringopenid profile email

Outcome : outcome.

OidcCallbackNode : échange le code contre des tokens et décode l’id_token.

Faites défiler le tableau
PropriétéTypeDéfaut
providerNamestring (obligatoire)Aucun
tokenEndpointstring (obligatoire)Aucun
clientIdstring (obligatoire)Aucun
clientSecretstring, secret""
redirectUristring (obligatoire)Aucun
trustEmailVerifiedbooleanfalse

Outcomes : true / false.

OAuth2CallbackNode : variante d’OidcCallbackNode pour les providers OAuth2 sans id_token (GitHub, LinkedIn…).

Faites défiler le tableau
PropriétéTypeDéfaut
providerNamestring (obligatoire)Aucun
tokenEndpointstring (obligatoire)Aucun
clientIdstring (obligatoire)Aucun
clientSecretstring, secret (obligatoire)Aucun
redirectUristring (obligatoire)Aucun

Outcomes : true / false.

FetchUserInfoNode : appelle le UserInfo endpoint avec l’access_token obtenu.

Faites défiler le tableau
PropriétéTypeDéfaut
userInfoEndpointstring (obligatoire)Aucun

Outcome : outcome.

NormalizeProfileNode : mappe les claims spécifiques au provider vers un schéma d’attributs standard.

Faites défiler le tableau
PropriétéTypeDéfaut
subjectClaimstringsub
emailClaimstringemail
nameClaimstringname
emailVerifiedClaimstringemail_verified

Outcome : outcome.

EmailVerifiedDecisionNode : décide selon le claim email_verified renvoyé par le provider social. Aucune propriété configurable. Outcomes : true / false.

AutoProvisionUserNode : crée un compte TOSIAM local à partir du profil social normalisé, s’il n’existe pas déjà. Aucune propriété configurable. Outcomes : true / false.

SocialAccountLinkingNode : recherche un compte local déjà lié à la paire (provider, subject). Aucune propriété configurable. Outcomes : found / not_found.

Mis à jour le