# Has anyone succeeded in using discourse as sso provider for nextcloud? Share recipe?

**URL:** https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430
**Category:** Support
**Created:** [18 במרץ,‏ 2017,‏ 5:59pm UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430 "2017-03-18T17:59:03Z")
**Posts on this page:** 16
**Page:** 1

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [18 במרץ,‏ 2017,‏ 5:59pm UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/1 "2017-03-18T17:59:03Z")

</div>

Hi all - I am interested in setting up a few small community sites with discourse plus [nextcloud](https://nextcloud.com) for document and media content sharing. It would be loverly and preferable to have SSO with discourse as SSO provider. If anyone has succeeded in doing this and can share a recipe here on how to do it I’d appreciate it. Thanks! 🌱

The communities I am looking at creating are for my own geographically dispersed family, my neighborhood, and my son’s school.

I might also be interested in setting up a nextcloud for the organization I work for that already has an active community website. Though my organization’s community uses discourse, it uses wordpress as SSO auth now. Down the pike I’m also interested in flipping that around so we can benefit from features reliant on discourse as SSO auth.

Edit: this seems to be the page - I will be exploring this today and will let others know what I come up with if anything. 🙂 Any guidance along the way much appreciated.

[https://docs.nextcloud.com/server/11/admin\_manual/configuration\_server/sso\_configuration.html](https://docs.nextcloud.com/server/11/admin_manual/configuration_server/sso_configuration.html)

---

<div class="post-metadata">

### Author: ![bangarang](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/bangarang/32/63023_2.png) [@bangarang](https://meta.discourse.org/u/bangarang)
#### Post date: [15 באוגוסט,‏ 2017,‏ 4:44pm UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/2 "2017-08-15T16:44:22Z")

</div>

i’ve quite the same usecases, where i want to use discourse as the SSO provider for nextcloud.

are there any updates on this?

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [17 באוגוסט,‏ 2017,‏ 2:35am UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/3 "2017-08-17T02:35:05Z")

</div>

Not that I am aware of. Could you ask at the nextcloud community?

---

<div class="post-metadata">

### Author: ![paroga](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paroga/32/120571_2.png) [@paroga](https://meta.discourse.org/u/paroga)
#### Post date: [4 בנובמבר,‏ 2017,‏ 1:54am UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/4 "2017-11-04T01:54:01Z")

</div>

it’s not a perfect implementation, but it does its job for me:

[https://github.com/paroga/user\_discourse](https://github.com/paroga/user_discourse)

---

<div class="post-metadata">

### Author: ![paroga](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paroga/32/120571_2.png) [@paroga](https://meta.discourse.org/u/paroga)
#### Post date: [8 בינואר,‏ 2022,‏ 2:15pm UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/6 "2022-01-08T14:15:30Z")

</div>

The [Social login app](https://apps.nextcloud.com/apps/sociallogin) has discourse support starting with version 4.10.

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [8 בינואר,‏ 2022,‏ 9:40pm UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/7 "2022-01-08T21:40:37Z")

</div>

Nice! I see discourse is not provided as a “builtin oauth provider” for the social login app in nextcloud. There are various ways to set this up using discourse - how did you do it? Would you mind providing a recipe?

I see also the app allows you to inherit groups from the auth provider, which is pretty neat. I’d love to be able to do this with my discourse/nextcloud setup.

There are also other nextcloud apps that appear to be relevant here but I have not tested them all. There’s OpenID Connect Login app. A [Discourse SSO](https://apps.nextcloud.com/apps/discoursesso) app also exists, but appears to be outdated/untested.

---

<div class="post-metadata">

### Author: ![paroga](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paroga/32/120571_2.png) [@paroga](https://meta.discourse.org/u/paroga)
#### Post date: [9 בינואר,‏ 2022,‏ 9:24am UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/8 "2022-01-09T09:24:29Z")

</div>

> [@tobiaseigen](#):
>
> There are various ways to set this up using discourse - how did you do it?

As written in my post you need version 4.10. Then there is a “Custom Discourse” option in the settings of social login.

 ![image](https://global.discourse-cdn.com/meta/original/3X/e/8/e87785a0f6b10f505ceffd2ffe93e780c8820dc3.png)

> [@tobiaseigen](#):
>
> There’s OpenID Connect Login app.

It has only OpenID Connect support, which is not provided by Discourse.

> [@tobiaseigen](#):
>
> A [Discourse SSO](https://apps.nextcloud.com/apps/discoursesso) app also exists.

That’s for the other direction, if you want do login into Discourse with your Nextcloud account.

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [9 בינואר,‏ 2022,‏ 8:47pm UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/9 "2022-01-09T20:47:48Z")

</div>

Thanks, Patrick! I installed the app now again and see the “Custom Discourse” option. It’s not yet explained in the documentation which is why I thought nothing had changed. Also on the [https://apps.nextcloud.com/apps/sociallogin](https://apps.nextcloud.com/apps/sociallogin) page there is a link to a broken link on the nextcloud support forum, so I am struggling to figure out where to talk about this app with the developers.

I have it working now, but the biggest problem I am having is that I cannot figure out how to enable this to be the only method for logging in for all existing users by default.

Second biggest problem is that the user details are not carrying over correctly from discourse to nextcloud. New users created in nextcloud get an automatically generated username in the form `[internal name]-[userid]` so in the case of my site e.g. `kb2-3797`. The name is carried over, but other profile details have to be fileld in again in nextcloud. Avatar is also not carried over.

I am also kind of wondering how the user will set up their username and password for the desktop or mobile client, when this is the only login method for the nextcloud web app. I guess they will have to know to go into their account prefs in the nextcloud web app to setup nextcloud login credentials.

Some other things I noticed:

- app settings are not reached via the `apps` section but via the administration settings sidebar. took me a minute to find. 🙂
- there are three sections in the admin settings for the app, and the top and bottom sections have save buttons but the middle one (for custom providers) does not. It’s not clear which one to use to save custom discourse settings. Answer: they both work the same way.
- there are many app settings. these appear to work best for my setup:
  - `disable auto create new users` = allows new users to be created in nextcloud if they exist in discourse
  - `create users with disabled account` = do not disable newly created users
  - `allow users to connect social logins with their account` = lets existing users opt in to logging in via discourse (⚠ not able to figure out how to default to allowing users to log in via discourse)
  - `update user profile every login` = syncs discourse groups with nextcloud groups each time they log in. (⚠ does not correctly sync username, name, bio and other profile info)
  - `do not prune not available user groups on login` (⚠ I don’t know what this does but enabled by default. I suspect it prevents removing the user from existing nextcloud groups if they are not mapped from discourse?)
  - `automatically create groups if they do not exist` = disabled because creates some fugly group names that replicate groups you do want (see below)
  - `restrict login for users without mapped groups` = disabled
  - `restict login for users without assigned groups` = disabled
  - `disable notify admins about new users` = disabled because helpful for me to see when new nextcloud users are created
  - ` hide default login` = encourages users to login via discourse though still possible to log in directly with the nextcloud username/email and password.  
 ![Screen Shot 2022-01-09 at 12.21.50 PM](https://global.discourse-cdn.com/meta/original/3X/0/4/04d9fb1f4932358f01f8836cbaeef3c7bd8d82e0.png)

- I lost admin access immediately the first time I tried it, before creating group mappings. To get it back, I had to go to the command line and run `occ group:adduser admin USERNAME`
- group mapping works super well! Most important was to add the mapping of `admins` → nextcloud `admin` so that admins in my forum have admin privs in nextcloud. I also was able to add mappings for groups used for secure categories, to also give access to secure folders in nextcloud related to those secure categories.

Inching ever closer!

---

<div class="post-metadata">

### Author: ![paroga](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paroga/32/120571_2.png) [@paroga](https://meta.discourse.org/u/paroga)
#### Post date: [9 בינואר,‏ 2022,‏ 11:12pm UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/10 "2022-01-09T23:12:52Z")

</div>

> [@tobiaseigen](#):
>
> I am struggling to figure out where to talk about this app with the developers.

I’d suggest [GitHub](https://github.com/zorn-v/nextcloud-social-login/issues).

> [@tobiaseigen](#):
>
> New users created in nextcloud get an automatically generated username in the form `[internal name]-[userid]` so in the case of my site e.g. `kb2-3797` .

IMHO that’s the best way to implement it, since the id is used primarily internal and not visible in many places to normal users.  
Nextcloud has no easy way to rename users, but Discourse has. Renaming a user in Discourse could lead to some strange behavior with Nextcloud if the names don’t match any more.

> [@tobiaseigen](#):
>
> The name is carried over, but other profile details have to be fileld in again in nextcloud. Avatar is also not carried over.

The `avatar_url` from [DiscourseConnect](https://meta.discourse.org/t/discourseconnect-official-single-sign-on-for-discourse-sso/13045) should [get passed](https://github.com/zorn-v/nextcloud-social-login/blob/36da1608bd6b26ad7b7d75cb76687357c2487be5/lib/Provider/CustomDiscourse.php#L135) to Nextcloud and [read there](https://github.com/zorn-v/nextcloud-social-login/blob/e0e6deef8288daf04f557c0f124c63b6e975f0c0/lib/Service/ProviderService.php#L465-L472). If you want to pass the `bio` too, a few lines in in the [branch responsible for the profile updates](https://github.com/zorn-v/nextcloud-social-login/blob/e0e6deef8288daf04f557c0f124c63b6e975f0c0/lib/Service/ProviderService.php#L457) should do the job.

> [@tobiaseigen](#):
>
> I am also kind of wondering how the user will set up their username and password for the desktop or mobile client

You should use [device passwords](https://docs.nextcloud.com/server/latest/user_manual/en/session_management.html#managing-devices) instead. The Nextcloud password could be different from the Discourse password, which would lead to confusion and skips the SSO.

> [@tobiaseigen](#):
>
> there are three sections in the admin settings for the app

I think these are general issues with the Nextcloud UI and not app specific.

> [@tobiaseigen](#):
>
> `hide default login` = encourages users to login via discourse though still possible to log in directly with the nextcloud username/email and password.

Set the `social_login_auto_redirect` option to `true` as described in the [config section](https://github.com/zorn-v/nextcloud-social-login/blob/be0ae3d26a28e1436f5fafa43c2aae03a63b74b5/README.md#config) if you want hide the Nextcloud login completely.

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [10 בינואר,‏ 2022,‏ 1:34am UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/11 "2022-01-10T01:34:25Z")

</div>

Awesome! Thanks, Patrick! Really appreciate the guidance.

I’ve opened an [issue over on github](https://github.com/zorn-v/nextcloud-social-login/issues/325) regarding my primary issue, which is that I’d like to make all users log in via discourse and currently cannot do it without giving the users instructions on how to switch over to discourse via the `social login connect` user preference.

I set `social_login_auto_redirect` now as you suggest and it will work well once everyone is set up to use discourse. 👍 As for now it works well for me personally but not for anyone else using these sites. They are not going to be allowed to log in. 😭

I’m not 100% clear on what you mean by device passwords - I looked at the link you provided but the screenshots of user prefs on that page don’t look the same as my nextcloud instance. Maybe we’re on a different version? I am on 23.0.0, on the stable update channel. 🤔 Or maybe there is an app I need to install?

The username, avatar and bio syncing is less urgent, though it would be nice to see it working properly. I don’t know why it shouldn’t be possible to update these details for the user upon each login. Maybe there are idiosyncracies with nextcloud that don’t play nicely with discourse in this case. For instance, discourse only allows one user per email address while it appears I am able to create a second nextcloud user with the same email address unless I prevent it using the `Prevent creating an account if the email address exists in another account` admin setting. Ideally it would just automatically connect these accounts based on the email address.

---

<div class="post-metadata">

### Author: ![paroga](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paroga/32/120571_2.png) [@paroga](https://meta.discourse.org/u/paroga)
#### Post date: [10 בינואר,‏ 2022,‏ 2:14am UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/12 "2022-01-10T02:14:36Z")

</div>

I’m not sure if I understand your current problem correctly, but I assume that your problem are the existing users, which have no “connected social login account”. When all users are connected everything would be fine?

As you wrote already yourself, the email is not unique in Nextcloud and therefore can not used safely for user mapping.

When I switched to the `sociallogin` app, I conencted the existing users with a simple SQL query. I exported the Discourse user list and inserted a mapping for the `[internal name]-[userid]` (e.g. `kb2-3797`) to the existing Nextcloud usernames into the `sociallogin_connect` table in the nextcloud database. What fields you use for mapping (e.g. username or email) depends on your setup.

> [@tobiaseigen](#):
>
> I’m not 100% clear on what you mean by device passwords

The screenshot seams a little bit outdated, but I have a very similar table (including the “button to create a new device-specific password”) when I open `/settings/user/security` on my Nextcloud 23.0 stable instance. Can you post a screenshot of your page?

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [10 בינואר,‏ 2022,‏ 2:48am UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/13 "2022-01-10T02:48:51Z")

</div>

It will not take me long to fix my existing users - I only have a few of them on my site. But in terms of a long term, replicable solution that will work for everyone seeking to use discourse as auth provider to nextcloud, it seems that it would make sense to only allow one user per email address and to match them up automatically based on the email address. There should be no need for users to do anything to make this happen.

Here’s what my `/settings/user/security` page looks like.

 ![Screen Shot 2022-01-09 at 6.43.52 PM](https://global.discourse-cdn.com/meta/original/3X/2/9/29d4145a19c2211686b29ba3cae821ee8664b4a8.png)

---

<div class="post-metadata">

### Author: ![paroga](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paroga/32/120571_2.png) [@paroga](https://meta.discourse.org/u/paroga)
#### Post date: [10 בינואר,‏ 2022,‏ 3:05am UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/14 "2022-01-10T03:05:47Z")

</div>

There is a “Create new app password” right at the end of the page. There you can create new credentials for e.g. desktop clients.

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [10 בינואר,‏ 2022,‏ 4:25am UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/15 "2022-01-10T04:25:40Z")

</div>

Ok, that makes sense though the language is all a bit confusing. I think I get it now. For new users who have never logged in directly to nextcloud and want to install the app, they need to use the Create new app password button to create a new “app password” to use for it. This ideally would be one password per device but doesn’t have to be.

I’ll keep following up on github to see if I can help clarify the documentation and get some of the integration issues ironed out. But for now I’d say @paroga you have finally solved this support request from back in 2017! 🥳

---

<div class="post-metadata">

### Author: ![tachibanalolo](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tachibanalolo/32/233762_2.png) [@tachibanalolo](https://meta.discourse.org/u/tachibanalolo)
#### Post date: [10 בינואר,‏ 2022,‏ 12:20pm UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/16 "2022-01-10T12:20:18Z")

</div>

> [@Set up your DiscourseConnect(DiscourseSSO) to SimpleSAMLphp, use your Discourse forum as a SAML IDP (Identify Provider)](https://meta.discourse.org/t/set-up-your-discourseconnect-discoursesso-to-simplesamlphp-use-your-discourse-forum-as-a-saml-idp-identify-provider/213654):
>
> Discourse has intergrated a [DiscourseConnect](https://meta.discourse.org/t/13045?silent=true) that allows you to change your Discourse into a SSO provider. You can find it in [“Using Discourse as an identity provider (SSO, DiscourseConnect)”](https://meta.discourse.org/t/using-discourse-as-an-identity-provider-sso-discourseconnect/32974) this article. However what it provides is not a standard SAML or Oauth protocol. So we need to use a [module](https://meta.discourse.org/t/using-discourse-as-an-identity-provider-sso-discourseconnect/32974/105) that created by Paul B. in Discourse forum. This is a module that allows us connect [DiscourseConnect](https://meta.discourse.org/t/13045?silent=true) to SimpleSAMLphp and then use SimpleSAMLphp to provide standard SAML login service protocol. In he…

I think you can have a look for the tutorial I have written.

I use this function to connect my NextCloud to my Discourse.

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [9 בפברואר,‏ 2022,‏ 12:20pm UTC](https://meta.discourse.org/t/has-anyone-succeeded-in-using-discourse-as-sso-provider-for-nextcloud-share-recipe/59430/17 "2022-02-09T12:20:22Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
