# 迁移白名单讨论到SSO的技术提升

**URL:** <https://meta.discourse.org/t/technical-lift-of-migrating-whitelisted-discourse-to-sso/214196>\
**Category:** General\
**Created:** [2022年一月7日 20:27 UTC](https://meta.discourse.org/t/technical-lift-of-migrating-whitelisted-discourse-to-sso/214196 "2022-01-07T20:27:06Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![mattdm](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mattdm/32/216484_2.png) [@mattdm](https://meta.discourse.org/u/mattdm)\
**Post date:** [2022年一月12日 05:05 UTC](https://meta.discourse.org/t/technical-lift-of-migrating-whitelisted-discourse-to-sso/214196/2 "2022-01-12T05:05:40Z")

</div>

目前，oidc 不支持群组同步。

> [@Does \`sso overrides groups\` work with Oauth2?](https://meta.discourse.org/t/does-sso-overrides-groups-work-with-oauth2/175606):
>
> I would like to use this feature. We’re on the Business hosted plan, so SAML is not available to us, so we’re using Oauth2 / OpenID Connect. I believe I have everything configured correctly (sso overrides groups is on, and oauth2 scope is set to openid profile email https://id.fedoraproject.org/scope/groups). I am a little confused about how Discourse uses the word SSO and what options appear where. However, we’re using sso overrides username and that works. Should I expect this to as well?

---

_[View the full topic](https://meta.discourse.org/t/technical-lift-of-migrating-whitelisted-discourse-to-sso/214196)._
