# Discourse OpenID Connect (OIDC)

**URL:** https://meta.discourse.org/t/discourse-openid-connect-oidc/103632
**Category:** Plugin
**Tags:** official, openid-connect, auth-plugins, included-in-core
**Created:** [2018 年 12 月 6 日午後 4:08 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632 "2018-12-06T16:08:20Z")
**Posts on this page:** 9
**Page:** 3

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [2025 年 7 月 16 日午後 9:41 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632/317 "2025-07-16T21:41:03Z")

</div>

🥳 このプラグインは、[Bundling more popular plugins with Discourse core](https://meta.discourse.org/t/bundling-more-popular-plugins-with-discourse-core/373574?u=tobiaseigen) の一部として、Discourse コアにバンドルされるようになりました。セルフホストでこのプラグインを使用している場合は、次回のアップグレード前に `app.yml` から削除する必要があります。

---

<div class="post-metadata">

### Author: ![hhf.technology](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hhf.technology/32/465129_2.png) [@hhf.technology](https://meta.discourse.org/u/hhf.technology)
#### Post date: [2025 年 7 月 24 日午前 6:52 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632/318 "2025-07-24T06:52:50Z")

</div>

はい、クライアントのために行いました。

---

<div class="post-metadata">

### Author: ![Steradiant](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/steradiant/32/360541_2.png) [@Steradiant](https://meta.discourse.org/u/Steradiant)
#### Post date: [2026 年 3 月 14 日午後 3:08 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632/320 "2026-03-14T15:08:31Z")

</div>

Discourse のグループと、私たちが持つ OIDC グループの一部を同期できるようになると大変助かります。この機能を提供するプルリクエストが存在していましたが、それ以上検討されなかったことがわかりました。

> <https://github.com/discourse/discourse/pull/34763/files>
>
> This PR allows mapping of OpenID Connect group membership to Discourse Group mem…bership.
> Of mapped Discourse groups, membership is (optionally) removed if the corresponding OpenID Connect group membership is not present.
> 
> This is a feature requested several times
> (e.g.
> https://meta.discourse.org/t/mapping-groups-or-roles-using-keycloak/304277
> https://meta.discourse.org/t/does-sso-overrides-groups-work-with-oauth2/175606/13
> https://meta.discourse.org/t/managing-group-membership-via-authentication/175950/32 \[and others above\])
> and the feature has been mentioned as #pr-welcome
> (https://meta.discourse.org/t/managing-group-membership-via-authentication/175950/30).
> 
> I've also added in a match\_by\_username option since this fits our use-case migrating from Crowd.
> 
> Apologies if the code is insufficient, I'm not a native ruby developer! If tests are required please could you point me at documentation that might help me with writing those?
> 
> Thank you!
> 
> PS Thanks for Discourse!

これを Discourse の機能に組み込むことは可能でしょうか？

---

<div class="post-metadata">

### Author: ![Steradiant](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/steradiant/32/360541_2.png) [@Steradiant](https://meta.discourse.org/u/Steradiant)
#### Post date: [2026 年 5 月 3 日午後 7:43 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632/321 "2026-05-03T19:43:05Z")

</div>

ユーザーが所属するグループのメンバーではなくなった場合、自動的に削除されますか？

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [2026 年 5 月 4 日午前 11:10 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632/322 "2026-05-04T11:10:54Z")

</div>

はい、そうです 👍

---

<div class="post-metadata">

### Author: ![Steradiant](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/steradiant/32/360541_2.png) [@Steradiant](https://meta.discourse.org/u/Steradiant)
#### Post date: [2026 年 5 月 4 日午前 11:41 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632/323 "2026-05-04T11:41:12Z")

</div>

ええと、実際には私のテスト結果と一致しませんね。

---

<div class="post-metadata">

### Author: ![attalbialami](https://avatars.discourse-cdn.com/v4/letter/a/f0a364/32.png) [@attalbialami](https://meta.discourse.org/u/attalbialami)
#### Post date: [2026 年 5 月 6 日午前 7:31 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632/324 "2026-05-06T07:31:18Z")

</div>

皆さんこんにちは。OpenID Connect プラグインを使用しており、`openid connect authorize parameters` を介して `/authorize` リクエストにカスタムパラメータを渡そうとしていますが、安定して動作しないようです。

これは公式にサポートされていますか？もしそうでない場合、IdP にカスタムコンテキストを送信するための推奨方法はどのようなものでしょうか？

ありがとうございます！  
@david

---

<div class="post-metadata">

### Author: ![sistason](https://avatars.discourse-cdn.com/v4/letter/s/b5a626/32.png) [@sistason](https://meta.discourse.org/u/sistason)
#### Post date: [2026 年 5 月 14 日午後 4:58 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632/325 "2026-05-14T16:58:19Z")

</div>

こんにちは、

このプラグインは長年問題なく動作していましたが、初めて、末尾にアンダースコア（例：許可されていないユーザー名）で終わるユーザー名を持つ SSO ユーザーに遭遇しました。

そのユーザーは Discourse にログインできません。OIDC がアンダースコアを除いたユーザー名でアカウント作成を試みているようです。これは問題ないはずですが、そのアカウントが既に存在している場合（ユーザー名 `foo` は存在し、ユーザー名 `foo_` は「アカウントが既に存在します」というエラーでログインできない）、どこかでなりすましの試みが行われているようです。

ユーザー名 `foo` のユーザーに、「アカウント作成を試みました」または「アカウントのメールアドレス変更を試みましたが、そのメールアドレスは既に使用されています」というメールが届きます。

これは `foo_` の最初のログイン時、つまり SSO によるアカウント作成時に発生します。つまり、`foo_` は `foo` としてアカウント作成を試みますが、その名前は既に使用されているため失敗します。しかし、なぜ元の `foo` のユーザーにその通知メールが届くのでしょうか？

> あなたは \\<discourse\\> でアカウント作成を試みました、またはアカウントのメールアドレスを \\<foo のメールアドレス\\> に変更しようとしましたが、そのメールアドレスは既に使用されています。

OIDC において `username` と `username_` が混在する問題に対する解決策、あるいは認証中に Discourse が無効なユーザー名をどのように扱うかを設定する方法はありますか？

---

<div class="post-metadata">

### Author: ![mixman68](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mixman68/32/355057_2.png) [@mixman68](https://meta.discourse.org/u/mixman68)
#### Post date: [2026 年 5 月 27 日午後 4:34 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632/326 "2026-05-27T16:34:25Z")

</div>

こんにちは

このプラグンの前回の編集ありがとうございます。しかし、OIDC で管理者を同期するにはどうすればよいでしょうか？

ありがとうございます

[Previous page](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632.md?page=2)
