also on https://forum.xwiki.org/t/oidc-allowed-groups-prefix/14419/8?u=schnutz It looks like the “allowed group” is only working, when at least one group is sent (based on the prefix, if set). I’ve invited a guest user in our tenant, but this user has no xwiki-relevant group. And this user can login and doesn’t get the error “it’s not a member of the following group”. Maybe the “lookup” on the empty group-set doesn’t work for allowed-groups. This is the part of the logs:
Only “checking allowed groups” and that’s it. |