# Discourse OpenID Connect (OIDC)

**URL:** <https://meta.discourse.org/t/discourse-openid-connect-oidc/103632>\
**Category:** Plugin\
**Tags:** official, openid-connect, auth-plugins, included-in-core\
**Created:** [2018年十二月6日 16:08 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632 "2018-12-06T16:08:20Z")\
**Posts on this page:** 1\
**Showing post:** 320

<div class="post-metadata">

**Author:** ![Steradiant](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/steradiant/32/360541_2.png) [@Steradiant](https://meta.discourse.org/u/Steradiant)\
**Post date:** [2026年三月14日 15:08 UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632/320 "2026-03-14T15:08:31Z")

</div>

我们希望能将 Discourse 中的某些群组与我们已有的 OIDC 群组同步。我们发现有一个拉取请求（PR）提供了此功能，但未被进一步考虑：

> <https://github.com/discourse/discourse/pull/34763/files>
>
> This PR allows mapping of OpenID Connect group membership to Discourse Group mem…bership.
> Of mapped Discourse groups, membership is (optionally) removed if the corresponding OpenID Connect group membership is not present.
> 
> This is a feature requested several times
> (e.g.
> https://meta.discourse.org/t/mapping-groups-or-roles-using-keycloak/304277
> https://meta.discourse.org/t/does-sso-overrides-groups-work-with-oauth2/175606/13
> https://meta.discourse.org/t/managing-group-membership-via-authentication/175950/32 \[and others above\])
> and the feature has been mentioned as #pr-welcome
> (https://meta.discourse.org/t/managing-group-membership-via-authentication/175950/30).
> 
> I've also added in a match\_by\_username option since this fits our use-case migrating from Crowd.
> 
> Apologies if the code is insufficient, I'm not a native ruby developer! If tests are required please could you point me at documentation that might help me with writing those?
> 
> Thank you!
> 
> PS Thanks for Discourse!

是否可以将此功能纳入 Discourse 的功能中？

---

_[View the full topic](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632)._
