OIDC User being removed from Organisation #1479

Open
opened 2026-04-05 19:30:22 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @joshdinsdale on 5/16/2025

Added my Pocket ID admin user to Pangolin and set it to have the Admin role.

Open an incognito browser tab and connect to one of my proxied resources that is Uprotected in Pangolin and uses OIDC to auth directly with pocket touch. I am redirected to Pocket Touch, login and amsucesfully redirected to the resource.
I open another tab, and connect to a Protected resource, i get the Pangolin login page and choose the pocket id login option, i am already authed but am then told by Pangolin that i do not have access.

In my other browser logged into Pangolin as admin, i browse to users for the resource and find that my pocket id user no longer shows in the user list. If i go to Server Admin I can see the users in the list here.

Some mechanism in Pangolin is removing this user from the site.

*Originally created by @joshdinsdale on 5/16/2025* Added my Pocket ID admin user to Pangolin and set it to have the Admin role. Open an incognito browser tab and connect to one of my proxied resources that is Uprotected in Pangolin and uses OIDC to auth directly with pocket touch. I am redirected to Pocket Touch, login and amsucesfully redirected to the resource. I open another tab, and connect to a Protected resource, i get the Pangolin login page and choose the pocket id login option, i am already authed but am then told by Pangolin that i do not have access. In my other browser logged into Pangolin as admin, i browse to users for the resource and find that my pocket id user no longer shows in the user list. If i go to Server Admin I can see the users in the list here. Some mechanism in Pangolin is removing this user from the site.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/pangolin#1479