mirror of
https://github.com/go-vikunja/vikunja.git
synced 2026-08-31 03:46:56 -05:00
EmailFallback only fallbacks to local user #668
Open
opened 2025-11-01 21:01:28 -05:00 by GiteaMirror
·
7 comments
No Branch/Tag Specified
main
renovate/rollup-4.x
renovate/danielroe-provenance-action-digest
renovate/dev-dependencies
renovate/postgres-18
renovate/markdown-it-15.x
renovate/basic-ftp-6.x
renovate/major-dev-dependencies
pr-swarm-assets
fix-rootpath-relative-defaults
feat-mcp
task-detail-sidebar-redesign
screenshots/task-detail-sidebar
consolidate-data-folder
fix-multiline-add-task-order
gh-readonly-queue/main/pr-3363-654bb9493053299350c37d355cb426e045d72353
feat-project-templates
feat-soft-delete-projects
feat-run-as-user
claude/task-event-field-changes-ws73g2
feat-audit-sinks
claude/per-user-feature-toggles-vqlg8x
docs-v2-query-param
claude/veans-question-xBFkq
spike-huma-openapi3
claude/investigate-swagger3-support-nyyUa
feat-list-view-buckets
ci-mysql-8-test
codex/analyze-codebase-for-email-task-feature
csv-import-feature
claude/email-reply-comments-wpdcQ
fix-oidc-pkce-support
fix/overview-subtasks-expand
feat/bucket-select-task-detail
claude/review-bot-design-plan-cf5C3
claude/project-scoped-api-tokens-KTqR3
claude/explore-openclaw-integration-KQEzg
claude/project-scoped-api-tokens-yv5KS
fix-duplicate-close-button
feat-list-view-sorting
feat/official-vite-sentry-plugin
feat/highlight-overdue-tasks
feat/add-enter-key-form-submission-handling
feat/TipTap-nits
feat/update-caldavtimetotimestamp-parsing
feat-phosphor-icons
wip-plans
claude/investigate-issue-2173-llKme
fix-description-text-drag
feat-custom-keyboard-shortcuts
pr-1845-ci
codex/fix-drag-and-drop-behavior-inconsistency
copilot/add-clickable-labels-for-filtering
copilot/fix-issue-1786
playwright-migration
fix-kanban-repeating-wip
copilot/fix-1498
feature/replace-axios
codex/upgrade-to-tailwind-4.1.8-using-pnpm
codex/add-cypress-test-for-avatar-types
feature/biome
feature/oxc
codex/update-flexsearch-to-0.8.205
4r6ni9-codex/fix-deprecated-sass-@import-usage
codex/fix-deprecated-sass-@import-usage
codex/add-cypress-test-for-task-list-refresh-fix
codex/fix-quick-add-magic-not-adding-tasks
codex/fix-all-type-errors
codex/fix-mimetype-for-docs.json
feature/caldav-from-scratch
feature/gh-actions-hetzner
fix-ci
feat/new-logger
jyte-better-dev-config
feat/add-team-member-with-enter
fix/button-and-icon-types
fix/notifications-component-name-collision
feature/null-time
renovate/tailwindcss-4.x
feature/unplugin-vue-router
fix/deprecated-import
feature/zod-schema
renovate/golangci-golangci-lint-1.x
fix/tiptap-editor-reactive-destructuring
release/0.24
feat/improve-add-task
fix/saved-filter-search
feat/webp-and-avif-attachment-previews
feature/migrate-back-to-bulma
fix/sass-add-missing-list-import
feature/sticky-demo-bar
fix/gantt-view-switch
feature/typesense-position-join
feature/focus-visible
dependencies/golangci-lint
feature/better-filter-syntax
fix/tiptap-task-list
renovate/github.com-golang-jwt-jwt-v4-5.x
feature/hide-forbidden-related-tasks
renovate/golang-1.x
release/0.20
release/0.17
release/0.16
release/0.15
release/0.14
v2.5.0
v2.4.0
v2.3.0
v2.2.2
v2.2.1
v2.2.0
v2.1.0
v2.0.0
v1.1.0
v1.0.0
v1.0.0-rc4
v1.0.0-rc3
v1.0.0-rc2
v1.0.0-rc1
v1.0.0-rc0
v0.24.6
v0.24.5
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.0
v0.22.1
v0.22.0
0.21.0
v0.21.0
v0.20.4
v0.20.5
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.2
v0.19.1
v0.19.0
vue3
v0.18.1
v0.18.0
v0.17.1
v0.17.0
v0.16.1
v0.16.0
v0.15.1
v0.15.0
v0.14.1
v0.14.0
v0.13.1
v0.13
v0.12
v0.11
v0.10
v0.9
v0.8
v0.7
v0.6
v0.5
v0.4
v0.3
v0.2
v0.1
Labels
Clear labels
area/api
area/attachments
area/auth
area/avatars
area/backup-restore
area/caldav
area/calendar-view
area/comments
area/config
area/database
area/desktop
area/docker
area/email
area/favorites
area/filters
area/frontend
area/gantt
area/i18n
area/import-export
area/internal-code
area/kanban
area/labels
area/list-view
area/mobile
area/notifications
area/permissions
area/projects
area/pwa
area/recurring-tasks
area/reminders
area/search
area/shortcuts
area/subtasks
area/sync
area/table-view
area/task-editor
area/task-metadata
area/task-relations
area/teams
area/theming
area/time-tracking
area/typesense
area/views
area/webhooks
bug
changes requested
concern/accessibility
concern/performance
concern/regression
concern/ux
confirmed
db/mysql
dependencies
enhancement
good first issue
help wanted
integration/inbound
integration/outbound
kind/bug
kind/feature
needs reproduction
pull-request
pull-request
pull-request
pull-request
question
security
support
upstream issue
waiting for reply
wontfix
Mirrored from GitHub Pull Request
Mirrored from GitHub Pull Request
Mirrored from GitHub Pull Request
Mirrored from GitHub Pull Request
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/vikunja#668
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @maggch97 on GitHub (Oct 16, 2025).
Description
https://github.com/go-vikunja/vikunja/blob/a5e2fbbe6975275201a95c6fefe347798de90579/pkg/modules/auth/openid/openid.go#L285
I'm not sure why here's this limitation. But for my use case, I switch to another oidc provider, EmailFallback does not work for my case.
For most website, it's normal that I can sign up with my Google account and then login with my Github account, if they have the same email address.
Could we remove the IssuerLocal limitation?
Vikunja Version
latest
Browser and version
No response
Can you reproduce the bug on the Vikunja demo site?
Please select
Screenshots
No response
@maggch97 commented on GitHub (Oct 16, 2025):
What I can think of is that the system does not require unique email address for oidc users. But I think it's not a good design that multiple users in this system can share a same email.
@maggch97 commented on GitHub (Oct 16, 2025):
I can imagine some fixes:
@kolaente commented on GitHub (Oct 19, 2025):
What does not work about it for you?
Since we don't control the email address, but the provider does, we don't have control over its uniqueness or anything really. That's why we don't use the email as an identifier for login.
@maggch97 commented on GitHub (Oct 20, 2025):
Migrate from A OIDC provider to B OIDC provider. A user has same email in different providers, but the issuer and subject are different.
Vikunja community also has a simillar feedback: https://community.vikunja.io/t/oidc-map-login-to-existing-user/2116/15
I have a PR for this https://github.com/go-vikunja/vikunja/issues/1672
@kolaente commented on GitHub (Oct 21, 2025):
If you only want to migrate, I would prefer if this was a one-time cli command due to the security implications of allowing this.
It would adjust the issuer in the database or even better, just tell it "migrate this user from this provider to that provider as configured in the config" and it will just update it.
Then again, it might be fine as you proposed in the PR since it's configurable. How are other tools solving this?
@maggch97 commented on GitHub (Oct 22, 2025):
I agree with you that a one time migration should fix my problem.
As what I know, headscale also had a similar discussion before https://github.com/juanfont/headscale/issues/1990. They used email before and finally choose to use iss+sub to identify a user, because some providers allow users to modify their username and email.
I'm fine with one time migration. Another scenario I’m considering is something like Cloudflare: I can sign in to the same account with either GitHub or Google as long as they share the same email. I didn't need this flow yet, but my understanding is that if the OIDC provider is trusted, then this flow should be secure. The key point is that the instance maintainer should ensure the provider is trusted, otherwise, without email fallback, the instance is still not secure.
Adding a new config option would increase both configuration and ongoing maintenance complexity. I’m planning to solve my issue with a one time migration. For the PR you can decide to merge or not, I'm ok with both.
@maggch97 commented on GitHub (Oct 22, 2025):
Migration with cli also needs some code change because issuer and subject are not supported to be updated with current cli. I will have a PR later.