fix(grafana): add email/login/name_attribute_path for Authentik OIDC — Grafana was falling back to GitHub-style <api_url>/emails (404 'Error getting email address'), breaking OAuth login; read identity from userinfo claims instead
This commit is contained in:
@@ -76,6 +76,13 @@ grafana.ini:
|
|||||||
auth_url: https://authentik.riotpiao.com/application/o/authorize/
|
auth_url: https://authentik.riotpiao.com/application/o/authorize/
|
||||||
token_url: https://authentik.riotpiao.com/application/o/token/
|
token_url: https://authentik.riotpiao.com/application/o/token/
|
||||||
api_url: https://authentik.riotpiao.com/application/o/userinfo/
|
api_url: https://authentik.riotpiao.com/application/o/userinfo/
|
||||||
|
# Read identity straight from the userinfo/id_token claims. Without these,
|
||||||
|
# Grafana falls back to the GitHub-style "<api_url>/emails" call, which
|
||||||
|
# Authentik doesn't serve — request 404s with "Error getting email address"
|
||||||
|
# and the whole OAuth login fails.
|
||||||
|
email_attribute_path: email
|
||||||
|
login_attribute_path: preferred_username
|
||||||
|
name_attribute_path: name
|
||||||
role_attribute_path: "contains(groups[*], 'grafana-admins') && 'Admin' || 'Viewer'"
|
role_attribute_path: "contains(groups[*], 'grafana-admins') && 'Admin' || 'Viewer'"
|
||||||
use_pkce: false
|
use_pkce: false
|
||||||
use_refresh_token: false
|
use_refresh_token: false
|
||||||
|
|||||||
Reference in New Issue
Block a user