Skip to content

docs(custom-idps): require a populated email claim; add mapping guidance and troubleshooting - #4106

Open
eslerm wants to merge 1 commit into
chainguard-dev:mainfrom
eslerm:eslerm/custom-idp-email-claim
Open

eslerm wants to merge 1 commit into
chainguard-dev:mainfrom
eslerm:eslerm/custom-idp-email-claim

Conversation

@eslerm

@eslerm eslerm commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

What

  • Adds a Required token claims section (and a requirements bullet) to the custom IdP overview, explaining that the token must carry a populated standard email claim — not just the requested email scope — and how to map a directory attribute to it.
  • Adds a per-provider Send a usable email claim note to the Okta, Microsoft Entra ID, Ping Identity, and Keycloak guides, next to the scope flag.
  • Adds a Troubleshooting entry for the support-portal redirect failure caused by a missing email.

Why

The setup requirements listed the email scope but not the requirement that the issued token actually carry a populated email claim. Providers that source email from a non-standard directory attribute (e.g. LDAP mail) pass sign-in but hand Chainguard an empty email, so the identity is created without one and email-dependent features such as the support portal stop working. Chainguard reads only the standard claim, so the fix is a customer-side attribute mapping — now documented, with a per-provider note and a troubleshooting entry tying the symptom to the cause.

@vercel

vercel Bot commented Sep 30, 2026

Copy link
Copy Markdown

@eslerm is attempting to deploy a commit to the Chainguard Team on Vercel.

A member of the Team first needs to authorize it.

@netlify

netlify Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for ornate-narwhal-088216 ready!

Name Link
🔨 Latest commit 6cd43f6
🔍 Latest deploy log https://app.netlify.com/projects/ornate-narwhal-088216/deploys/6ac001a235e2480008401604
😎 Deploy Preview https://deploy-preview-4106--ornate-narwhal-088216.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@eslerm
eslerm force-pushed the eslerm/custom-idp-email-claim branch from b4f51e8 to 6e65485 Compare October 1, 2026 00:06
@thimbleforth

Copy link
Copy Markdown

Should the "Send a usable email claim" text be added to the Ping and/or Keycloak pages as well, if we're already doing Okta and Entra?

@eslerm
eslerm marked this pull request as ready for review October 1, 2026 23:14
@eslerm
eslerm requested a review from a team as a code owner October 1, 2026 23:14

@matthewhelmke matthewhelmke left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you for writing this up!

@matthewhelmke
matthewhelmke force-pushed the eslerm/custom-idp-email-claim branch from 6e65485 to 0b0627f Compare October 2, 2026 11:57
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
chainguard-docs-preview Ready Ready Preview Oct 2, 2026 7:13pm UTC

Request Review

…roubleshooting

The setup requirements listed the email scope but not that the issued
token must carry a populated standard email claim. Providers that source
email from a non-standard directory attribute (e.g. LDAP mail) pass
sign-in but hand Chainguard an empty email, so the identity is created
without one and email-dependent features such as the support portal stop
working. Chainguard reads only the standard claim, so the fix is a
customer-side attribute mapping.

- Add a "Required token claims" section and a requirements bullet to the
  custom IdP overview.
- Add a per-provider "Send a usable email claim" note to the Okta,
  Microsoft Entra ID, Ping Identity, and Keycloak guides.
- Add a troubleshooting entry for the support-portal redirect failure.

This branch was successfully deployed

1 active deployment
Preview — 6cd43f6b Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants