From 17eb445323a7374e8570e162f79916150b6311cf Mon Sep 17 00:00:00 2001
From: clokep
backchannel_logout_enabled
: set to true
to process OIDC Back-Channel Logout notifications.
+Those notifications are expected to be received on /_synapse/client/oidc/backchannel_logout
.
+Defaults to false
.
backchannel_logout_ignore_sub
: by default, the OIDC Back-Channel Logout feature checks that the
+sub
claim matches the subject claim received during login. This check can be disabled by setting
+this to true
. Defaults to false
.
You might want to disable this if the subject_claim
returned by the mapping provider is not sub
.
It is possible to configure Synapse to only allow logins if certain attributes match particular values in the OIDC userinfo. The requirements can be listed under -- cgit 1.5.1