[FED-004] Cross-Instance Identity Linking #87

Closed
opened 2026-01-29 23:29:16 +00:00 by jason.woltje · 0 comments
Owner

Phase 2: Authentik Integration

Handle identity across federated instances:

  • Same-email identity matching
  • Explicit identity linking
  • Federated user permissions (maxRole enforcement)
  • Cross-IdP trust relationships

Deliverables

  • FederatedIdentity model
  • Identity linking API
  • Email-based auto-linking (configurable)
  • Role ceiling enforcement for federated users

Dependencies

  • #85 CONNECT/DISCONNECT Protocol
  • #86 Authentik OIDC Integration
  • #83 Federation EPIC
## Phase 2: Authentik Integration Handle identity across federated instances: - Same-email identity matching - Explicit identity linking - Federated user permissions (maxRole enforcement) - Cross-IdP trust relationships ## Deliverables - [ ] FederatedIdentity model - [ ] Identity linking API - [ ] Email-based auto-linking (configurable) - [ ] Role ceiling enforcement for federated users ## Dependencies - #85 CONNECT/DISCONNECT Protocol - #86 Authentik OIDC Integration ## Related - #83 Federation EPIC
jason.woltje added this to the M7-Federation (0.0.7) milestone 2026-01-29 23:29:16 +00:00
jason.woltje added the authphase-2apiapip1 labels 2026-01-29 23:29:16 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: mosaic/stack#87